Skip to content

Pupy

Pupy is an open-source, cross-platform remote access trojan (RAT) and post-exploitation framework written mainly in Python.

Profile source: Mallory opens in a new tab

Pupy

Family profile

Pupy is an open-source, cross-platform remote access trojan (RAT) and post-exploitation framework written mainly in Python. The provided content describes capabilities on both Windows and Linux, including local information enumeration on Linux hosts and discovery of currently logged-on users on Windows. Pupy supports encrypted command-and-control communications, using SSL by default with additional RSA and AES transport options noted. One cited 2023 Decoy Dog activity cluster, reported by Infoblox, involved Pupy RAT operating over DNS command and control using TXT records.

The malware includes broad surveillance and collection functionality. It can access a connected webcam and capture pictures, record microphone audio, capture screenshots, and send screenshots, files, keylogger data, and recorded audio back to its C2 server. Credential access is a prominent capability in the content: Pupy can use LaZagne repeatedly for credential harvesting, including credentials from browsers, mail, WiFi, and other local sources as described for LaZagne generally, and it can execute both LaZagne and Mimikatz via PowerShell.

Pupy also supports execution and post-exploitation modules. The content states it has a module for loading and executing PowerShell scripts, can use PowerView to execute net user commands and create local system accounts, has a built-in port scanning module, and can enable or disable RDP connections as well as start a remote desktop session through a browser WebSocket client. A cited PowerShell session associated with Pupy showed deletion of Registry keys under HKCU:\Software\Classes\Folder* using Remove-Item -Recurse -Force, characterized in the source as cleanup of privilege-escalation artifacts. Overall, the content portrays Pupy as a multifunctional post-compromise framework supporting reconnaissance, credential theft, surveillance, remote administration, and exfiltration over its established C2 channel.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 8, 2026
Last activity
Aug 8, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • JP1

Leading providers

  • ALLIANCE INTELLIGENT TECHNOLOGIES PTE. LTD.1

Infrastructure traits

  • Hosting 1

Reported operators

Threat actors

1 named in public reporting
Magic Hound

...Word documents with malicious macros that executed PowerShells scripts to download Pupy.

MITRE ATT&CK

Pupy in ATT&CK

32 distinct techniques

Reporting

Research mentioning Pupy

Aug 3
Securelist

Incident response statistics and cases at educational institutions in Brazil | Securelist

Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.

Jul 15
Esentire

DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft | eSentire

eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.

Mar 9
Mitre Attack Website

Compromise Accounts, Technique T1586 - Enterprise | MITRE ATT&CK®

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.