Peppy

S0643

Malware.View on attack.mitre.org

About this malware

Peppy is a Python-based remote access Trojan, active since at least 2012, with similarities to Crimson.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1020
Automated Exfiltration

Peppy has the ability to automatically exfiltrate files and keylogs.

T1056.001
Keylogging

Peppy can log keystrokes on compromised hosts.

T1059.003
Windows Command Shell

Peppy has the ability to execute shell commands.

T1071.001
Web Protocols

Peppy can use HTTP to communicate with C2.

T1083
File and Directory Discovery

Peppy can identify specific files for exfiltration.

T1105
Ingress Tool Transfer

Peppy can download and execute remote files.

T1113
Screen Capture

Peppy can take screenshots on targeted systems.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Proofpoint Operation Transparent Tribe March 2016 Open source
    Huss, D. (2016, March 1). Operation Transparent Tribe. Retrieved June 8, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.