Palo Alto Networks Unit 42 reported that the Chinese espionage group Alloy Taurus deployed a new Linux variant of PingPull alongside a related backdoor, Sword2033, extending a malware family previously associated with Windows intrusions. The Linux PingPull sample, uploaded to VirusTotal in March 2023, communicated over HTTPS with yrhsywu2009.zapto[.]org on port 8443 and reused the same AES key and command structure seen in earlier PingPull activity, strengthening the link to the group.
Unit 42 also tied Sword2033 samples to overlapping infrastructure, including a sample configured to connect to 196.216.136[.]139 in South Africa, and connected the activity to earlier Alloy Taurus indicators such as 45.251.241[.]82. The infrastructure included a domain impersonating South African military branding, while sustained connections from an IP linked to an organization financing long-term urban infrastructure projects in Nepal suggested recent espionage activity targeting entities in South Africa and Nepal.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
A Linux PingPull sample named nztloader was uploaded to VirusTotal on March 7, 2023. Unit 42 identified it as a new Linux variant communicating over HTTPS with yrhsywu2009.zapto[.]org on port 8443.
Unit 42 reported that the domain yrhsywu2009.zapto[.]org was most recently hosted on 5.181.25[.]99 until early February 2023. This domain was later tied to both PingPull and Sword2033 samples.
The IP address 196.216.136[.]139 resolved to vpn729380678.softether[.]net from late December 2022 through mid-February 2023. Unit 42 also linked this infrastructure to a South Africa-themed impersonation domain pattern.
A second Sword2033 sample named Hopke was observed in July 2022. It was configured to connect to 196.216.136[.]139 for command and control.
In June 2022, Unit 42 published earlier research on PingPull and attributed the tool to Alloy Taurus. The later Linux and Sword2033 findings were linked back to this prior reporting.
The domain yrhsywu2009.zapto[.]org resolved to 45.251.241[.]82 for one day in April 2022. Unit 42 had previously listed that IP as an active indicator of compromise tied to Alloy Taurus.
Unit 42 reported that PingPull samples date back to September 2021, establishing the malware family's earlier use by Alloy Taurus. This predates later public reporting and newer platform variants.
Unit 42 assessed that Alloy Taurus, also known as GALLIUM and Softcell, has operated since at least 2012. The group has historically targeted telecommunications companies across Asia, Europe, and Africa.
Unit 42 reported that Alloy Taurus was using a new Linux variant of PingPull and a related backdoor called Sword2033. The report tied both malware families to shared infrastructure and noted recent activity affecting organizations in South Africa and Nepal.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.