PyGRPC is a compiled Python reverse SOCKS proxy used in a 2026 intrusion cluster attributed to a likely initial access broker associated with ransomware follow-on activity. It is protected with Pyarmor and is designed to provide covert network tunneling from compromised hosts back to operator-controlled infrastructure. PyGRPC communicates with command-and-control servers using gRPC over TLS and applies additional AES encryption to message payloads, indicating an emphasis on blending with legitimate encrypted traffic while adding another layer of protocol protection. In addition to reverse proxying, it can generate reconnaissance reporting for the operator. PyGRPC has been observed alongside other tooling including the GoGRPC backdoor family, BlindDoor, RevSocket, S3Siphon, and RSOX in campaigns that began with social engineering through Microsoft Teams vishing and Quick Assist remote access, followed by PowerShell-based staging on Windows enterprise systems. Its role in these operations is consistent with post-compromise access enablement, internal network reachability, and operator-controlled tunneling within targeted corporate environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
ThreatLabz analyzed the functionality of these tools along with the command-and-control (C2) communication methods used by the attackers.
The threat actor also deploys SOCKS proxy tools that also use gRPC or WebSockets to communicate with the C2 server.
RevSocket : proxy SOCKS inverse en Go ... PyGRPC : proxy SOCKS inverse en Python ... RSOX : ... proxy SOCKS relay
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compiled Python reverse SOCKS proxy protected with Pyarmor, using gRPC over TLS plus additional AES encryption and capable of sending reconnaissance reports.
A Python-based tool used in the same operation; the IoC list describes it as 'PyGRPC and reconnaissance tool,' indicating reconnaissance support alongside backdoor functionality.
Additional malware used in the same campaigns alongside GoGRPC.
A compiled Python reverse SOCKS proxy that uses gRPC over TLS plus AES-encrypted payloads, supports tunnel establishment/closure, and can generate and send reconnaissance reports to C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.