Peppy RAT
Description
(Proofpoint) Peppy is a Python-based RAT with the majority of its appearances having similarities or definite overlap with MSIL/Crimson RAT appearances. Peppy communicates to its C&C over HTTP and utilizes SQLite for much of its internal functionality and tracking of exfiltrated files. The primary purpose of Peppy may be the automated exfiltration of potentially interesting files and keylogs. Once Peppy successfully communicates to its C&C, the keylogging and exfiltration of files using configurable search parameters begins. Files are exfiltrated using HTTP POST requests.
In addition to keylogging and the exfiltration of files, Peppy is also capable of accepting commands from its C&C to update itself, disable itself, exfiltrate a specific file, uninstall itself, execute a shell command, take screenshots, spawn a reverse shell, and download a remote file and execute it.
Names
Name |
---|
Peppy RAT |
Peppy Trojan |
Category
Malware
Type
- Backdoor
- Keylogger
- Info stealer
- Downloader
- Exfiltration
Information
Malpedia
Alienvault Otx
Other Information
Uuid
23a7f4a8-9826-47a8-a7e8-1c4da9f44ca6
Last Card Change
2022-12-29