PIPEDANCE is a custom Windows backdoor used by a state-sponsored threat group for post-compromise operations. It uses encrypted Windows named-pipe communications as a bidirectional internal command-and-control proxy, supporting lateral movement and deployment of additional implants. Its command set supports interactive command execution, process termination, file and directory enumeration, process discovery, working-directory changes, and writing operator-supplied content to files. PIPEDANCE can test HTTP, DNS, ICMP, and TCP connectivity to identify usable egress paths. It executes additional shellcode through process injection, including thread-execution hijacking on 32-bit systems and Heaven’s Gate and Native API-based methods on 64-bit systems. It was observed in an intrusion against a Vietnamese organization in late 2022 alongside Cobalt Strike, and associated activity involved injection into legitimate Windows utilities. Initial access and the initial loading chain were not confirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
“Create random process with hijacked token from provided PID and inject shellcode” and “Open process from provided PID and inject shellcode.”
“Open process from provided PID and inject shellcode (32bits) — PID (thread hijack), shellcode” and the corresponding 64-bit command.
The report's observed adversary techniques list includes 'Token impersonation/theft.'
PIPEDANCE then encrypts the buffer containing the previous process details with RC4 and then writes the encrypted data back to the client pipe.
“Create random process with hijacked token from provided PID and inject shellcode” and “Open process from provided PID and inject shellcode.”
“Open process from provided PID and inject shellcode (32bits) — PID (thread hijack), shellcode” and the corresponding 64-bit command.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom state-sponsored post-compromise backdoor that uses named pipes as its primary command-and-control channel. It supports reconnaissance and discovery, lateral movement, deployment of additional implants, command execution, file and process enumeration, process termination, file writing, token hijacking, thread-hijacking and shellcode injection, and HTTP/DNS/ICMP/TCP connectivity checks.
A malware implant/backdoor referenced as present on an overlapping host in the related REF4322 environment, suggesting access handoff or tool replacement involving SPECTRALVIPER.
Previously observed malware on an endpoint in the REF4322 environment, mentioned in connection with a SPECTRALVIPER infection that appeared to replace or coexist with prior tooling.
Windows named-pipe backdoor for covert post-compromise operations and lateral movement. It provides command execution and interactive shell access, process and file discovery, file writing, network egress/connectivity checks (DNS, ICMP, TCP, HTTP), encrypted pipe communications using RC4, and process injection via thread hijacking or Heaven's Gate.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.