Description
PingPull is a remote access trojan written in Visual C++ that the GALLIUM threat group has used since at least June 2022. Its campaigns have targeted telecommunications companies, financial institutions, and government entities across countries including Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam.
Stats
- First seen
- July 2022
- Last seen
- October 2026
Also known as
Pingpull
MITRE ATT&CK techniques
15 techniques across 7 tactics.
Associated groups
Alert name variants
| Alert Name |
|---|
| Linux.Trojan.PingPull |
| Win64.Backdoor.Pingpull |