PipeDown is a malware component associated with DPRK-linked cryptocurrency intrusion activity, particularly operations tracked as GOLDEN CHOLLIMA. It has been observed in campaigns targeting cryptocurrency and fintech organizations and is part of a broader specialized toolkit that includes DevobRAT, HTTPHelper, and Anycon. Reported shellcode overlaps among these families indicate shared development lineage or code reuse within a coordinated malware ecosystem tied to North Korean financially motivated operations.
PipeDown is linked to intrusion sets focused on digital-asset theft rather than broad indiscriminate deployment. Its known context places it within campaigns that used trojanized cryptocurrency-themed software and related fintech-focused tradecraft. The malware’s association with GOLDEN CHOLLIMA suggests use in operations aimed at compromising organizations in the cryptocurrency sector, supporting follow-on access and theft objectives. Available information supports its role as part of a modular intrusion toolkit used against fintech and cryptocurrency targets, but does not establish enough detail to confidently assign a more specific standalone family classification or enumerate distinct technical behaviors beyond its use in those financially motivated campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CrowdStrike Intelligence has observed eight different Jeus and AppleJeus variants in campaigns targeting cryptocurrency entities as well as shellcode overlaps between PipeDown, DevobRAT, HTTPHelper, and Anycon — forming a specialized fintech targeting toolkit.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Part of a specialized fintech-targeting toolkit associated through shellcode overlaps in GOLDEN CHOLLIMA campaigns.
Referenced as a related malware family showing shellcode overlap with later Jeus/AppleJeus variants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.