PipeDown is malware associated with DPRK-linked GOLDEN CHOLLIMA activity and appears in reporting as part of a specialized fintech-targeting toolkit. The provided content states that CrowdStrike observed shellcode overlaps between PipeDown, DevobRAT, HTTPHelper, and Anycon, indicating shared code or closely related development within this malware set. PipeDown is mentioned in the context of GOLDEN CHOLLIMA operations targeting cryptocurrency and fintech organizations, particularly in economically advanced regions including the United States, Canada, South Korea, India, and Western Europe. GOLDEN CHOLLIMA is described as conducting steady, smaller-scale cryptocurrency thefts, historically using Jeus/AppleJeus-style lures, recruitment fraud, malicious Python packages, and Chromium zero-days, and in at least one late-2024 fintech intrusion pivoting into a victim cloud environment to access IAM configurations and divert cryptocurrency to adversary-controlled wallets. Based on the provided content, PipeDown should be understood as part of this broader DPRK fintech intrusion ecosystem; however, the specific functionality, infection chain position, persistence mechanisms, and standalone indicators of compromise for PipeDown are not provided in the source material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Subsequent variants exhibit shellcode overlaps with Pipedown, Devobrat, Httphelper, and Anycon.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Specialized malware/implant associated with DPRK fintech/crypto targeting toolkit; noted for shellcode overlap with related implants.
Referenced as a related malware family showing shellcode overlap with later Jeus/AppleJeus variants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.