Last seven days
- First activity
- Sep 20, 2026
- Last activity
- Sep 20, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
Poison Ivy, also known as PIVY, is a Windows remote-access trojan/backdoor used in targeted intrusion activity.
Profile source: Mallory opens in a new tabPoison Ivy
Poison Ivy, also known as PIVY, is a Windows remote-access trojan/backdoor used in targeted intrusion activity. It provides operators with remote command-line access, system-information collection, file-transfer capabilities, keystroke logging, application-window-title discovery, and local staging of collected data. It supports persistence through Windows Registry-based autorun mechanisms, Active Setup, service registration or modification, and device-registration changes. Poison Ivy can inject malicious DLLs into processes, deploy a rootkit component, obscure embedded strings, and encrypt command-and-control communications with Camellia. It has been loaded through DLL side-loading and has been used by several espionage-focused groups, including menuPass/APT10, DragonOK, GALLIUM, and Soft Cell. Documented activity has included targeting Japanese academic, pharmaceutical, manufacturing, and high-technology organizations.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
[4] https://www.fireeye.com/blog/threat-research/2013/08/operation-molerats-middle-east-cyber-attacks-using-poison-ivy.html
GALLIUM established persistence for PoisonIvy by created a scheduled task.
In addition to using PlugX and Poison Ivy (PIVY), both known to be used by the group...
Soft Cell used DLL side-loading to covertly load PoisonIvy into memory on the victim machine.
Three of the backdoors, NFlog, PoisonIvy, and NewCT have previously been publicly associated with DragonOK.
PittyTiger Enfal Ghost RAT MimiKatz Poison Ivy APT24
PlugX includes config data like PoisonIvy – e.g., C2 hostname/IP/domain, installed service name/registry value
ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat
ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat
An example of this is ‘bae.cisconline[.]net’, which suggested intended targeting of BAE Systems and was found in a ‘Poison Ivy’ sample.
Capabilities and Resources • RATs • Commercial or open-source RAT • Poison Ivy, ZxShell
TA428 was also particularly active, using PoisonIvy, Cotx RAT, Tmanger, and nccTrojan to attack East Asian organizations such as Mongolia.
Other malware families that have been seen relating to PKPLUG include ‘usual suspects’ Poison Ivy, Zupdax and 9002.
GALLIUM ... Examples of associated tools: PlugX, ChinaChopper, Poison Ivy ... ; Mustang Panda ... Examples of associated tools: ... PoisonIvy
该WEB服务器上存放了多个不同配置的恶意脚本和可执行文件,一个目录下是一组攻击样本,最终运行的Poison Ivy ShellCode(Poison Ivy是一个远程管理工具)都会连接一个单独C2地址。
Symantec has the following protection in place to protect customers against Elfin attacks: ... Backdoor.Breut ...
该组织擅长对目标实施鱼叉攻击和水坑攻击,植入修改后的ZXShell、Poison Ivy、XRAT商业木马,并使用动态域名作为其控制基础设施。
Earlier campaigns used legacy Poison Ivy RAT shellcode variants and ZxShell via spear-phishing and watering hole attacks.
Злоумышленники также используют и хорошо известное ВПО: PlugX, ShadowPad, Poison Ivy, модифицированный вариант PcShare и публичный шелл ReVBShell.
RedFoxtrot’s infrastructure is linked to an assortment of PlugX, Poison Ivy, Royal Road, PCShare, and IceFog samples used by the group.
This jar file had a MD5 of 51aff823274e9d12b1a9a4bbbaf8ce00. It exploited CVE-2013-1493 and dropped a Poison Ivy RAT with the MD5 2B6605B89EAD179710565D1C2B614665. This Poison Ivy RAT connected to a command and control server at 9ijhh45[.]zapto[.]org over port 443 using a password of ‘ult4life’.
...deployment of closed-source remote access Trojans (RATs) such as Poison Ivy and ZxShell...
Tools QuasarRAT, RedLeaves, PoisonIvy, ChChes, QuasarRAT Loader, PlugX, ANEL, Cobalt Strike
Open-source reporting indicates that adobesupport[.]net was used to serve the Poison Ivy SKYLINE variant masquerading as an Adobe Flash installer in mid-2019.
In March and April 2016, a series of emails laced with an exploit for CVE-2015-2545 were detected... they used a new variant of a widely available backdoor known as PoisonIvy (from which the name of the group, SPIVY, is derived).
Tools: Sysupdate, China Chopper, OwaAuth, ZxShell, Gh0st RAT, PoisonIvy, Hunter, PlugX, Enfal, HttpBrowser, 9002, ASPXSpy, HyperBro
...typically using publicly available RATs such as PoisonIvy...
Exploited software
MITRE ATT&CK
Reporting
eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.
Sophos has identified a new PlugX USB worm variant spreading through removable media in outbreaks across Papua New Guinea, Ghana, Mongolia, Zimbabwe, and Nigeria, using DLL sideloading with legitimate AvastSvc.exe, a malicious wsc.dll, and an encrypted PlugX payload. The malware hides files on infected USB drives, gathers host reconnaissance, and steals Office and PDF documents up to 300 MB, storing them in encrypted form under RECYCLER.BIN with base64-obfuscated filenames before attempting exfiltration to infrastructure including 45.142.166[.]112. The activity aligns with the long-running PKPLUG espionage cluster, which researchers have previously attributed with high confidence to a Chinese nation-state adversary targeting victims in and around Southeast Asia, including Xinjiang, Mongolia, Myanmar, and Taiwan. Earlier reporting tied PKPLUG to malware families including PlugX, Poison Ivy, 9002, Zupdax, Farseer, and the Android spyware HenBox, and documented overlapping infrastructure, DLL sideloading, registry-based persistence, and surveillance-focused collection against regional targets, reinforcing the assessment that the new worm is part of a broader intelligence-gathering campaign.
Multiple cyber-espionage operations targeted الفلسطينيين, activists, and organizations in the Palestinian territories with politically themed phishing lures and fake documents that delivered custom backdoors including Micropsia, Spark, Pierogi, and Scote. Reporting from Cisco Talos, Cybereason, and Palo Alto Networks links the activity to long-running Middle East-focused threat actors Arid Viper and MoleRATs (also known as the Gaza Cybergang), which repeatedly used Arabic-language decoys tied to regional politics, social-engineering archives hosted on services such as Dropbox and Egnyte, malicious RTF and Word files, and self-extracting executables to infect victims. The malware families provided persistent remote access and espionage capabilities including host reconnaissance, command execution, keylogging, screenshot capture, audio recording, file transfer, and HTTP-based command-and-control. Researchers said the operators also used evasion and targeting checks such as security-product discovery, Arabic language or keyboard validation, packers, and abuse of third-party platforms including Pastebin, Google+, and URL shorteners to hide infrastructure and retrieve C2 data. Across the campaigns, analysts observed largely consistent tradecraft over several years, indicating sustained intelligence collection against Palestinian political and civil-society targets despite repeated public exposure.
Invicta Stealer is being spread through phishing emails that impersonate GoDaddy refund invoices, using an infection chain that begins with a malicious HTML attachment and progresses through ZIP, LNK, HTA, and PowerShell stages before installing the information-stealing malware. Researchers said the malware’s developer has promoted the family on Telegram, YouTube, and GitHub, including a free builder that appears to have lowered the barrier to entry for other threat actors and increased the stealer’s circulation. Once executed by the victim, Invicta Stealer gathers extensive host and user data, including browser information, Discord data, cryptocurrency wallet contents, Steam and KeePass artifacts, installed application details, and files from Desktop and Documents, then compresses and exfiltrates the data to a Discord webhook or other command-and-control endpoint. The campaign aligns with common user execution tradecraft in phishing-led intrusions, and the malware also uses anti-analysis features such as encrypted strings, syscalls, and multithreading while collecting system and application context from infected machines.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.