Skip to content

Poison Ivy

Poison Ivy, also known as PIVY, is a Windows remote-access trojan/backdoor used in targeted intrusion activity.

Profile source: Mallory opens in a new tab

Poison Ivy

Family profile

Poison Ivy, also known as PIVY, is a Windows remote-access trojan/backdoor used in targeted intrusion activity. It provides operators with remote command-line access, system-information collection, file-transfer capabilities, keystroke logging, application-window-title discovery, and local staging of collected data. It supports persistence through Windows Registry-based autorun mechanisms, Active Setup, service registration or modification, and device-registration changes. Poison Ivy can inject malicious DLLs into processes, deploy a rootkit component, obscure embedded strings, and encrypt command-and-control communications with Camellia. It has been loaded through DLL side-loading and has been used by several espionage-focused groups, including menuPass/APT10, DragonOK, GALLIUM, and Soft Cell. Documented activity has included targeting Japanese academic, pharmaceutical, manufacturing, and high-technology organizations.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 20, 2026
Last activity
Sep 20, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • JP1

Leading providers

  • ARTERIA Networks Corporation1

Samples

Recent associated samples

Reported operators

Threat actors

27 named in public reporting
Molerats

[4] https://www.fireeye.com/blog/threat-research/2013/08/operation-molerats-middle-east-cyber-attacks-using-poison-ivy.html

GALLIUM

GALLIUM established persistence for PoisonIvy by created a scheduled task.

menuPass

In addition to using PlugX and Poison Ivy (PIVY), both known to be used by the group...

Soft Cell

Soft Cell used DLL side-loading to covertly load PoisonIvy into memory on the victim machine.

DragonOK

Three of the backdoors, NFlog, PoisonIvy, and NewCT have previously been publicly associated with DragonOK.

apt24

PittyTiger Enfal Ghost RAT MimiKatz Poison Ivy APT24

APT1

PlugX includes config data like PoisonIvy – e.g., C2 hostname/IP/domain, installed service name/registry value

Aluminum Saratoga

ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat

BRONZE DUDLEY

ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat

APT14

An example of this is ‘bae.cisconline[.]net’, which suggested intended targeting of BAE Systems and was found in a ‘Poison Ivy’ sample.

PoisonVine

Capabilities and Resources • RATs • Commercial or open-source RAT • Poison Ivy, ZxShell

TA428

TA428 was also particularly active, using PoisonIvy, Cotx RAT, Tmanger, and nccTrojan to attack East Asian organizations such as Mongolia.

PKPLUG

Other malware families that have been seen relating to PKPLUG include ‘usual suspects’ Poison Ivy, Zupdax and 9002.

Mustang Panda

GALLIUM ... Examples of associated tools: PlugX, ChinaChopper, Poison Ivy ... ; Mustang Panda ... Examples of associated tools: ... PoisonIvy

GreenSpot

该WEB服务器上存放了多个不同配置的恶意脚本和可执行文件,一个目录下是一组攻击样本,最终运行的Poison Ivy ShellCode(Poison Ivy是一个远程管理工具)都会连接一个单独C2地址。

APT33

Symantec has the following protection in place to protect customers against Elfin attacks: ... Backdoor.Breut ...

毒云藤

该组织擅长对目标实施鱼叉攻击和水坑攻击,植入修改后的ZXShell、Poison Ivy、XRAT商业木马,并使用动态域名作为其控制基础设施。

APT-C-01

Earlier campaigns used legacy Poison Ivy RAT shellcode variants and ZxShell via spear-phishing and watering hole attacks.

Space Pirates

Злоумышленники также используют и хорошо известное ВПО: PlugX, ShadowPad, Poison Ivy, модифицированный вариант PcShare и публичный шелл ReVBShell.

APT41

RedFoxtrot’s infrastructure is linked to an assortment of PlugX, Poison Ivy, Royal Road, PCShare, and IceFog samples used by the group.

APT19

This jar file had a MD5 of 51aff823274e9d12b1a9a4bbbaf8ce00. It exploited CVE-2013-1493 and dropped a Poison Ivy RAT with the MD5 2B6605B89EAD179710565D1C2B614665. This Poison Ivy RAT connected to a command and control server at 9ijhh45[.]zapto[.]org over port 443 using a password of ‘ult4life’.

APT-Q-20

...deployment of closed-source remote access Trojans (RATs) such as Poison Ivy and ZxShell...

CTG-5938

Tools QuasarRAT, RedLeaves, PoisonIvy, ChChes, QuasarRAT Loader, PlugX, ANEL, Cobalt Strike

RedFoxtrot

Open-source reporting indicates that adobesupport[.]net was used to serve the Poison Ivy SKYLINE variant masquerading as an Adobe Flash installer in mid-2019.

SPIVY

In March and April 2016, a series of emails laced with an exploit for CVE-2015-2545 were detected... they used a new variant of a widely available backdoor known as PoisonIvy (from which the name of the group, SPIVY, is derived).

Threat Group-3390

Tools: Sysupdate, China Chopper, OwaAuth, ZxShell, Gh0st RAT, PoisonIvy, Hunter, PlugX, Enfal, HttpBrowser, 9002, ASPXSpy, HyperBro

admin@338

...typically using publicly available RATs such as PoisonIvy...

Exploited software

Vulnerabilities linked to Poison Ivy

14 CVEs

MITRE ATT&CK

Poison Ivy in ATT&CK

71 distinct techniques

Techniques

71 techniques
T1027 Obfuscated Files or Information T1203 Exploitation for Client Execution T1497 Virtualization/Sandbox Evasion T1059.003 Windows Command Shell T1189 Drive-by Compromise T1566 Phishing T1566.003 Spearphishing via Service T1112 Modify Registry T1056.001 Keylogging T1074.001 Local Data Staging T1053.005 Scheduled Task T1005 Data from Local System T1547.014 Active Setup T1573.001 Symmetric Cryptography T1547.001 Registry Run Keys / Startup Folder T1105 Ingress Tool Transfer T1480.002 Mutual Exclusion T1543.003 Windows Service T1010 Application Window Discovery T1014 Rootkit T1055.001 Dynamic-link Library Injection T1573 Encrypted Channel T1055 Process Injection T1219 Remote Access Tools T1204 User Execution T1574.001 DLL T1071 Application Layer Protocol T1566.001 Spearphishing Attachment T1001.003 Protocol or Service Impersonation T1036.005 Match Legitimate Resource Name or Location T1041 Exfiltration Over C2 Channel T1195.002 Compromise Software Supply Chain T1547 Boot or Logon Autostart Execution T1620 Reflective Code Loading T1622 Debugger Evasion T1059 Command and Scripting Interpreter T1570 Lateral Tool Transfer T1113 Screen Capture T1046 Network Service Discovery T1125 Video Capture T1566.002 Spearphishing Link T1003 OS Credential Dumping T1036 Masquerading T1071.001 Web Protocols T1137 Office Application Startup T1057 Process Discovery T1583.001 Domains T1007 System Service Discovery T1021 Remote Services T1082 System Information Discovery T1210 Exploitation of Remote Services T1033 System Owner/User Discovery T1129 Shared Modules T1012 Query Registry T1027.007 Dynamic API Resolution T1560 Archive Collected Data T1568 Dynamic Resolution T1106 Native API T1090 Proxy T1218.007 Msiexec T1059.005 Visual Basic T1070.004 File Deletion T1574.011 Services Registry Permissions Weakness T1574.010 Services File Permissions Weakness T1584 Compromise Infrastructure T1074 Data Staged T1218 System Binary Proxy Execution T1059.001 PowerShell T1568.001 Fast Flux DNS T1053 Scheduled Task/Job T1555 Credentials from Password Stores

Reporting

Research mentioning Poison Ivy

Jul 15
Esentire

DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft | eSentire

eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.

Jan 1
Sophos Threat Research

A new APT uses DLL side-loads to “KilllSomeOne” | SOPHOS

Sophos has identified a new PlugX USB worm variant spreading through removable media in outbreaks across Papua New Guinea, Ghana, Mongolia, Zimbabwe, and Nigeria, using DLL sideloading with legitimate AvastSvc.exe, a malicious wsc.dll, and an encrypted PlugX payload. The malware hides files on infected USB drives, gathers host reconnaissance, and steals Office and PDF documents up to 300 MB, storing them in encrypted form under RECYCLER.BIN with base64-obfuscated filenames before attempting exfiltration to infrastructure including 45.142.166[.]112. The activity aligns with the long-running PKPLUG espionage cluster, which researchers have previously attributed with high confidence to a Chinese nation-state adversary targeting victims in and around Southeast Asia, including Xinjiang, Mongolia, Myanmar, and Taiwan. Earlier reporting tied PKPLUG to malware families including PlugX, Poison Ivy, 9002, Zupdax, Farseer, and the Android spyware HenBox, and documented overlapping infrastructure, DLL sideloading, registry-based persistence, and surveillance-focused collection against regional targets, reinforcing the assessment that the new worm is part of a broader intelligence-gathering campaign.

Jan 1
Sophos Threat Research

A border-hopping PlugX USB worm takes its act on the road | SOPHOS

Jan 1
Zscaler Threat Labz

Middle East users targeted by Molerats APT | Zscaler Blog

Multiple cyber-espionage operations targeted الفلسطينيين, activists, and organizations in the Palestinian territories with politically themed phishing lures and fake documents that delivered custom backdoors including Micropsia, Spark, Pierogi, and Scote. Reporting from Cisco Talos, Cybereason, and Palo Alto Networks links the activity to long-running Middle East-focused threat actors Arid Viper and MoleRATs (also known as the Gaza Cybergang), which repeatedly used Arabic-language decoys tied to regional politics, social-engineering archives hosted on services such as Dropbox and Egnyte, malicious RTF and Word files, and self-extracting executables to infect victims. The malware families provided persistent remote access and espionage capabilities including host reconnaissance, command execution, keylogging, screenshot capture, audio recording, file transfer, and HTTP-based command-and-control. Researchers said the operators also used evasion and targeting checks such as security-product discovery, Arabic language or keyboard validation, packers, and abuse of third-party platforms including Pastebin, Google+, and URL shorteners to hide infrastructure and retrieve C2 data. Across the campaigns, analysts observed largely consistent tradecraft over several years, indicating sustained intelligence collection against Palestinian political and civil-society targets despite repeated public exposure.

Jan 1
Cybereason

New Cyber Espionage Campaigns Targeting Palestinians - Part 2: The Discovery of the New, Mysterious Pierogi Backdoor

Jan 1
Cybereason

New Malware Arsenal Abusing Cloud Platforms in Middle East Espionage Campaign

Nov 17
Mitre Attack

Molerats, Operation Molerats, Gaza Cybergang, Group G0021 | MITRE ATT&CK®

May 25
Cyble Blog Historic

Invicta Stealer Spreads Via Fake GoDaddy Refund Invoices

Invicta Stealer is being spread through phishing emails that impersonate GoDaddy refund invoices, using an infection chain that begins with a malicious HTML attachment and progresses through ZIP, LNK, HTA, and PowerShell stages before installing the information-stealing malware. Researchers said the malware’s developer has promoted the family on Telegram, YouTube, and GitHub, including a free builder that appears to have lowered the barrier to entry for other threat actors and increased the stealer’s circulation. Once executed by the victim, Invicta Stealer gathers extensive host and user data, including browser information, Discord data, cryptocurrency wallet contents, Steam and KeePass artifacts, installed application details, and files from Desktop and Documents, then compresses and exfiltrates the data to a Discord webhook or other command-and-control endpoint. The campaign aligns with common user execution tradecraft in phishing-led intrusions, and the malware also uses anti-analysis features such as encrypted strings, syscalls, and multithreading while collecting system and application context from infected machines.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.