Skip to content
Malware family

Hupigon

Hupigon, also known as Graftor, is a backdoor Trojan malware family.

Profile source: Mallory opens in a new tab

Hupigon

Family profile

Hupigon, also known as Graftor, is a backdoor Trojan malware family. It has been detected under the names Backdoor.Win32.Hupigon, Trojan.Win32.Hupigon, Backdoor.Win32.Graftor, and Trojan.Win32.Graftor, with additional vendor aliases including Trojan.Win32.Boht and Backdoor:Win32/Bezigate. According to the provided content, its first known detection dates to November 2008. Hupigon is primarily used to connect victim systems into a botnet (described as a zombie network) and is operated through a command-and-control center supervising infected hosts. The malware can spread through networks to infect additional computers, but the content states it does not spread automatically like a worm. The family contains many variants, which the content says are written in Borland Delphi. Samples are usually portable executable files and may be packed with UPX. The content attributes Hupigon to Red Apollo and lists affected platforms as Windows, Linux, iOS, and Android.

MITRE ATT&CK

Hupigon in ATT&CK

4 distinct techniques

Reporting

Research mentioning Hupigon

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.