Hupigon, also known as Graftor, is a long-running Windows remote access Trojan and backdoor family that has been active since at least the mid-2000s. It is commonly associated with remote command-and-control of infected hosts and has historically appeared under multiple vendor names. The family has also been described as supporting botnet-style operation in which compromised systems are centrally managed by an operator.
Hupigon provides attackers with persistent remote access to victim machines and has been associated with data theft and delivery of additional malware. Reported capabilities include keylogging, password theft, webcam monitoring, and rootkit-style functionality intended to conceal malicious activity. It has also been characterized as a trojan that can facilitate follow-on compromise and broader post-exploitation activity.
Observed delivery includes phishing campaigns in which victims are enticed to click links that download and execute the malware. A documented large-volume campaign targeted faculty and students at U.S. colleges and universities using adult-themed lures, indicating opportunistic crimeware-style distribution at scale. Hupigon has also been referenced in broader discussions of publicly available RATs used by multiple actors.
The malware has historical associations with APT reporting, but at least some observed campaigns have been assessed as financially motivated crimeware rather than state-directed operations. Hupigon has also been linked by some reporting to Chinese threat activity, and the family is known to have many variants, including Delphi-based samples. Overall, Hupigon is best understood as an established RAT/backdoor family used for covert access, surveillance, credential collection, and staging of additional malicious activity on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
It allows actors to access the infected machine, has rootkit functionality, webcam monitoring, and the ability to log keystrokes and steal passwords.
It allows actors to access the infected machine, has rootkit functionality, webcam monitoring, and the ability to log keystrokes and steal passwords.
Ramnit and Hupigon are both long-standing trojans that can facilitate data theft and the delivery of additional malware. Either could have been involved in the theft of credentials attackers later reused to access the housing authority’s system
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Long-standing trojan mentioned as capable of facilitating data theft and delivery of additional malware.
A remote access trojan with rootkit functionality that allows attackers to access infected machines, monitor webcams, log keystrokes, and steal passwords. In this campaign it was delivered via adult-dating lure emails that downloaded an executable and established DNS-based initial command-and-control communication.
A backdoor trojan used to connect victim PCs into a botnet. It can spread through networks to infect other computers, though it does not spread automatically like a worm and is instead operated through command-and-control infrastructure. The family has many variants and is written in Borland Delphi.
2008 Agent.BTZ Asprox Conficker Fun.exe Hupigon Mariposa MonaRonaDona OpenCandy
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.