Pierogi is a Windows backdoor malware variant associated with the Gaza Cybergang / Arid Viper / APT-C-23 ecosystem and tracked as part of the broader Micropsia family. The malware was first observed in 2019, and public reporting cited in the content notes that the most widely used variant was described by Cybereason in February 2020 as “Pierogi.” Facebook’s April 2021 reporting lists Pierogi among Arid Viper’s continuing Micropsia Windows variants alongside Primewire, Fgref, Sears, Rahman, PyMicropsia, and Glasswire.
High-confidence reporting in the content links Pierogi to espionage-focused activity targeting primarily Palestinian entities and, more broadly, Israeli and Palestinian victims. Gaza Cybergang is described as a suspected Hamas-aligned threat cluster active since at least 2012, targeting government, defense, energy, financial, media, technology, telecommunications, and civil society organizations, with primary objectives of intelligence collection and espionage. Arid Viper is described as targeting Palestinian and Israeli individuals and organizations, including government officials, Fatah members, student groups, security forces, and entities in defense, government, law enforcement, and political sectors.
Pierogi shares code and functional similarities with the newer Pierogi++ backdoor observed from 2022 through 2023. The content states that Pierogi++ is assessed to be based on Pierogi and that both share strings, reconnaissance techniques, and decoy document deployment patterns. Core backdoor functions shared between Pierogi and Pierogi++ include taking screenshots, executing commands, and downloading attacker-provided files. Earlier Pierogi samples reportedly used Ukrainian command strings including "vydalyty," "Zavantazhyty," and "Ekspertyza."
Observed delivery and tradecraft in related reporting indicate use of spear phishing, malicious documents, email attachments, link lures, archive files, and weaponized Office documents, often themed around Palestinian matters. Related campaigns used macros to deploy payloads and embedded malware in Base64-encoded form. Historical Pierogi command-and-control domains mentioned in the content include escanor[.]live and nicoledotson[.]icu; those domains were associated with Arid Viper. The content also notes that victims in a late 2020 suspected Arid Viper operation involving Pierogi were also infected with SharpStage and DropBook, strengthening ties between Molerats and Arid Viper.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tools include Molerat Loader, XtremeRAT, SharpStage, DropBook, Spark, Pierogi, PoisonIvy, and many others observed uniquely over the years.
We assess that Pierogi++ is based on an older malware strain named Pierogi, first observed in 2019.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Most samples are found to have a combination of the following features: ... Install a keylogger
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An older backdoor strain implemented in Delphi and Pascal, sharing code, strings, reconnaissance techniques, and decoy-document deployment behavior with Pierogi++. It supports screenshots, command execution, and file download, and was later associated with Arid Viper infrastructure and operations.
A malware/tool observed in Gaza Cybergang operations supporting espionage objectives.
Pierogi is listed as a named malware/tool in SentinelOne reporting on Gaza Cybergang activity targeting Hamas opposition.
Widely used Delphi/Free Pascal Micropsia variant used by Arid Viper for Windows espionage, supporting standard Micropsia-style check-ins and in some samples screenshot uploads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.