PingPull Malware

trojan horse

Security researchers with Palo Alto's Unit 42 discovered and analyzed a new strain of malware called PingPull. The new malware has RAT capabilities and is particularly difficult to detect.

PingPull is the newest tool in the arsenal of the GALLIUM advanced persistent threat actor, sometimes referred to as Softcell. Given the geolocation of entities targeted by GALLIUM and their mode of operation, as well as their use of malware and modes of operation already linked with known Chinese threat actors means that the GALLIUM outfit is very likely Chinese too and is sponsored by the state.

PingPull itself comes in three different variations that can use three different protocols to communicate with the malware's C2 servers, even if all three variants have the same capabilities.

The Trojan offers twelve different commands, using the cmd.exe Windows process as a reverse shell. Those commands include storage drive enumeration, all major operations with files, including conversion to hex, timestamping files and manipulating directories.

The malware can install a copy of itself as a service on the compromised machine, copying the description of the Iphlpsvc Windows service, in an attempt to dodge detection.

Communication between the trojan and its C2 infrastructure is encrypted using AES.

June 16, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.