Hupigon
Hupigon, also known as Graftor, is a long-running Windows remote access Trojan and backdoor family that has been active since at least the mid-2000s.
Profile source: Mallory opens in a new tabHupigon
Family profile
Hupigon, also known as Graftor, is a long-running Windows remote access Trojan and backdoor family that has been active since at least the mid-2000s. It is commonly associated with remote command-and-control of infected hosts and has historically appeared under multiple vendor names. The family has also been described as supporting botnet-style operation in which compromised systems are centrally managed by an operator.
Hupigon provides attackers with persistent remote access to victim machines and has been associated with data theft and delivery of additional malware. Reported capabilities include keylogging, password theft, webcam monitoring, and rootkit-style functionality intended to conceal malicious activity. It has also been characterized as a trojan that can facilitate follow-on compromise and broader post-exploitation activity.
Observed delivery includes phishing campaigns in which victims are enticed to click links that download and execute the malware. A documented large-volume campaign targeted faculty and students at U.S. colleges and universities using adult-themed lures, indicating opportunistic crimeware-style distribution at scale. Hupigon has also been referenced in broader discussions of publicly available RATs used by multiple actors.
The malware has historical associations with APT reporting, but at least some observed campaigns have been assessed as financially motivated crimeware rather than state-directed operations. Hupigon has also been linked by some reporting to Chinese threat activity, and the family is known to have many variants, including Delphi-based samples. Overall, Hupigon is best understood as an established RAT/backdoor family used for covert access, surveillance, credential collection, and staging of additional malicious activity on Windows systems.
Capabilities
- Credential Theft
- Defense Evasion
- Keylogging
- Persistence
- Post Exploitation
MITRE ATT&CK