s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.pingpull

📛 Threat Title

Malware family: PingPull

Category: PingPull First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.pingpull`. Printable name: PingPull.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.pingpull VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.pingpull

IOC database

Type
domain
Value
elf.pingpull
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.pingpull

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.pingpull

References (1)

Remediations (10)

  • web:attack.mitre.org

    PingPull is a remote access Trojan (RAT) written in Visual C++ that has been used by GALLIUM since at least June 2022. PingPull has been used to target telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam.

  • web:cybernews.com

    The FBI warns of a surge in ATM jackpotting attacks, with more than 700 incidents in 2025 alone. Hackers use Ploutus malware to force machines to dispense cash.

  • web:hivepro.com

    GALLIUM targeting telecommunications with new PingPull malware—discover tactics, IOCs, and mitigations , plus what's new on Hive Pro to strengthen your defenses.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the PingPull malware family including references, samples and yara signatures.

  • web:secoperations.wordpress.com

    China-linked Gallium APT employed a previously undocumented RAT, tracked as PingPull , in recent cyber espionage campaign targeting South Asia, Europe, and Africa. China-linked Gallium APT (aka Softcell) used a previously undocumented remote access Trojan dubbed PingPull in recent attacks aimed at organizations in Southeast Asia, Europe, and Africa. Researchers from Palo Alto Networks defined ...

  • web:socprime.com

    Their latest activity is characterized by APT's strive to evolve and expand the used malware toolsets. In their previous attacks, the Gallium hackers employed Gh0st RAT and Poison Ivy malware , this time striking with the PingPull RAT. The malware family called PingPull is characterized by outstanding stealthiness.

  • web:unit42.paloaltonetworks.com

    A PingPull malware variant for Linux has been found. We're also tracking a new backdoor attributed to Alloy Taurus called Sword2033.

  • web:www.csoonline.com

    The identification of a Linux variant of PingPull malware , as well as the recent use of the Sword2033 backdoor, shows Alloy Taurus continues to evolve its operations in support of its espionage ...

  • web:www.pcrisk.com

    PingPull malware overview The research done by Unit 42 suggests that PingPull is connected to the cyber crime group called GALLIUM, which is likely sponsored by the Chinese state. As mentioned in the introduction, PingPull is a RAT - a program capable of enabling remote access and control over compromised devices.

  • web:www.socinvestigation.com

    Researchers from Palo Alto Networks defined the PingPull RAT as a "difficult-to-detect" backdoor that leverages the Internet Control Message Protocol (ICMP) for C2 communications. Experts also found PingPull variants that use HTTPS and TCP for C2 communications instead of ICMP. The activity of the APT group was first reported by Microsoft in December 2019, when

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.