Hupigon
Hupigon, also known as Graftor, is a long-running Windows remote access Trojan and backdoor family that has been active since at least the mid-2000s.
Profile source: Mallory opens in a new tabHupigon
Family profile
Hupigon, also known as Graftor, is a long-running Windows remote access Trojan and backdoor family that has been active since at least the mid-2000s. It has been used to provide attackers with persistent remote control of compromised systems and has historically appeared in both criminal and espionage-linked activity. Security vendors have tracked related samples under multiple names, including Graftor and other vendor-specific detections, reflecting a broad and variant-rich family.
Hupigon is associated with classic RAT functionality, including remote access to infected hosts, keystroke logging, password theft, webcam monitoring, and rootkit-style capabilities intended to conceal malicious activity. Reporting also describes its use in command-and-control operations and botnet-style management of infected machines. The family has numerous variants, including Delphi-based builds, and some samples have been observed packed for evasion.
Observed delivery has included phishing campaigns in which victims were enticed to click links that downloaded and executed the malware. A notable high-volume campaign in 2020 primarily targeted faculty and students at U.S. colleges and universities using adult-themed lures, but the broader activity reached organizations across many sectors. Although Hupigon has historical associations with state-sponsored threat activity, at least some later campaigns were assessed as crimeware based on their scale, delivery patterns, and operational characteristics.
Hupigon is best characterized as a Windows-focused RAT/backdoor family used for remote compromise, surveillance, credential collection, and sustained attacker access.
Capabilities
- Credential Theft
- Defense Evasion
- Keylogging
- Persistence
- Post Exploitation
MITRE ATT&CK