Skip to main content
Mallory
MalwareUsed by 1 actor

Pierogi

Pierogi is a Windows malware variant in the Micropsia family used by the threat actor Arid Viper, also known as Desert Falcon and APT-C-23. Public reporting cited in the content identifies Pierogi as one of multiple Micropsia variants tracked alongside Primewire, Fgref, Sears, Rahman, PyMicropsia, and Glasswire. The most widely used variant was reported by Cybereason in February 2020 under the name “Pierogi.”

Based on the supporting content, Pierogi is associated with Arid Viper’s long-running cyber-espionage operations in the Middle East. Reporting links the broader actor to campaigns targeting primarily Palestinian individuals and organizations, including government officials, Fatah members, student groups, and security forces; other public reporting in the timeline also connects the group to operations against Israeli targets. Arid Viper relied heavily on social engineering, fake social media personas, phishing, and attacker-controlled infrastructure, including more than 100 websites used for malware hosting, credential theft, and command-and-control. Facebook’s April 2021 report states the group continued using and developing Micropsia Windows malware variants, including Pierogi.

High-confidence details specific to Pierogi in the provided content are limited to its identification as a Micropsia-family Windows malware variant used by Arid Viper/APT-C-23 and its mention in public reporting by Cybereason and SentinelOne. The provided content does not include distinct technical capabilities, infection chain details, or unique indicators of compromise specific to Pierogi itself.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Arid Viper

The most widely used variant we’ve seen was reported on by Cybereason in February 2020, which they called “Pierogi”.

via about fbabout.fb.com
MITRE ATT&CK

Techniques & procedures

11 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566.001Spearphishing AttachmentEvidence1

The malware is typically delivered through archive files or weaponized Office documents on Palestinian matters, written in English or Arabic.

Execution

1 technique
T1059Command and Scripting InterpreterEvidence2

Allow an attacker to run arbitrary commands

Persistence

2 techniques
T1547.001Registry Run Keys / Startup FolderEvidence1

some of the samples had the capability to also establish persistence via the Windows registry (Microsoft\Windows\CurrentVersion\Run).

T1547.009Shortcut ModificationEvidence1

They often do this by creating a shortcut to the malware in the AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup directory.

Privilege Escalation

2 techniques
T1547.001Registry Run Keys / Startup FolderEvidence1

some of the samples had the capability to also establish persistence via the Windows registry (Microsoft\Windows\CurrentVersion\Run).

T1547.009Shortcut ModificationEvidence1

They often do this by creating a shortcut to the malware in the AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup directory.

Credential Access

2 techniques
T1056.001KeyloggingEvidence1

Most samples are found to have a combination of the following features: ... Install a keylogger

T1555Credentials from Password StoresEvidence1

Most samples are found to have a combination of the following features: ... Extract and upload stored credentials

Collection

3 techniques
T1056.001KeyloggingEvidence1

Most samples are found to have a combination of the following features: ... Install a keylogger

T1113Screen CaptureEvidence1

Further, Pierogi++ samples implement in the same order the same backdoor functionalities as Pierogi: taking screenshots, command execution, and downloading attacker-provided files.

T1560Archive Collected DataEvidence1

Search for files of specific types and add them to RAR archives for exfiltration

Command and Control

3 techniques
T1001Data ObfuscationEvidence1

Use Base64 to obfuscate command and control communications

T1071Application Layer ProtocolEvidence1

Some Primewire samples utilize “multipart/form-data” for command and control check-ins... other samples combine the C2 parameters into a single “application/x-www-form-urlencoded” POST body.

T1105Ingress Tool TransferEvidence2

Allow an attacker to download and run arbitrary files

INDICATORS OF COMPROMISE

IOCs tracked for this family

8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
4 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
4 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app3 years ago
domain●●●●●●●●●●●●View more in app3 years ago
domain●●●●●●●●●●●●View more in app3 years ago
hash.sha1●●●●●●●●●●●●View more in app3 years ago
hash.sha1●●●●●●●●●●●●View more in app3 years ago
domain●●●●●●●●●●●●View more in app3 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching8

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping11

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.