Peppy RAT

Description

(Proofpoint) Peppy is a Python-based RAT with the majority of its appearances having similarities or definite overlap with MSIL/Crimson RAT appearances. Peppy communicates to its C&C over HTTP and utilizes SQLite for much of its internal functionality and tracking of exfiltrated files. The primary purpose of Peppy may be the automated exfiltration of potentially interesting files and keylogs. Once Peppy successfully communicates to its C&C, the keylogging and exfiltration of files using configurable search parameters begins. Files are exfiltrated using HTTP POST requests.

In addition to keylogging and the exfiltration of files, Peppy is also capable of accepting commands from its C&C to update itself, disable itself, exfiltrate a specific file, uninstall itself, execute a shell command, take screenshots, spawn a reverse shell, and download a remote file and execute it.

Names

Name
Peppy RAT
Peppy Trojan

Category

Malware

Type

  • Backdoor
  • Keylogger
  • Info stealer
  • Downloader
  • Exfiltration

Information

Malpedia

Alienvault Otx

Other Information

Uuid

23a7f4a8-9826-47a8-a7e8-1c4da9f44ca6

Last Card Change

2022-12-29