PITSTOP

S1123

Malware.View on attack.mitre.org

About this malware

PITSTOP is a backdoor that was deployed on compromised Ivanti Connect Secure VPNs during Cutting Edge to enable command execution and file read/write.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1059.004
Unix Shell

PITSTOP has the ability to receive shell commands over a Unix domain socket.

T1140
Deobfuscate/Decode Files or Information

PITSTOP can deobfuscate base64 encoded and AES encrypted commands.

T1205.002
Socket Filters

PITSTOP can listen and evaluate incoming commands on the domain socket, created by PITHOOK malware, located at `/data/runtime/cockpit/wd.fd` for a predefined magic byte sequence. PITSTOP can then duplicate the socket for further communication over TLS.

T1559
Inter-Process Communication

PITSTOP can listen over the Unix domain socket located at `/data/runtime/cockpit/wd.fd`.

T1573.002
Asymmetric Cryptography

PITSTOP has the ability to communicate over TLS.

Groups that use it0

None recorded.

Campaigns1

References1

  1. Mandiant Cutting Edge Part 3 February 2024 Open source
    Lin, M. et al. (2024, February 27). Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts. Retrieved March 1, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.