Description
PipeMon is a multi-stage modular backdoor used by the Winnti Group.
Stats
- First seen
- February 2023
- Last seen
- September 2026
Also known as
Pipemon
MITRE ATT&CK techniques
23 techniques across 7 tactics.
TA0003 Persistence
TA0004 Privilege Escalation
TA0005 Stealth
TA0007 Discovery
TA0011 Command and Control
Associated groups
Alert name variants
| Alert Name |
|---|
| Win64.Backdoor.Pipemon |
| Win64.Trojan.PipeMon |