PeddleCheap is a C++-based backdoor and initial-access loader first documented by Mandiant (now part of Google Cloud Security) in May 2022, primarily used by cybercriminal groups for gaining footholds in enterprise networks before deploying ransomware or other payloads. It belongs to the category of loaders/backdoors, often sold on underground forums as a commodity malware, and is associated with the threat actor tracked as UNC2891 (also known as "PeddleCheap group").
PeddleCheap employs process injection techniques (MITRE ATT&CK T1055.012) to inject malicious code into legitimate processes such as svchost.exe or explorer.exe for stealth. It uses HTTP/HTTPS for command-and-control communication, with C2 payloads encrypted using XOR and RC4; the malware periodically beacons to hardcoded IP addresses or domains, and can execute arbitrary shell commands, download additional payloads, and exfiltrate data. Persistence is achieved via creating a scheduled task (MITRE ATT&CK T1053.005) or adding a Registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value named "PeddleCheap". Evasion techniques include checking for sandbox environments by verifying system uptime, CPU core count, and the presence of certain analysis tools; it also terminates itself if it detects common debugging or antivirus processes.
PeddleCheap first appeared in the wild in late 2021, but came to widespread attention after Mandiant's 2022 report detailing its use in intrusions targeting the healthcare, government, and critical manufacturing sectors. In one notable incident reported by Mandiant in early 2023, the threat actor used PeddleCheap to deliver Cobalt Strike beacons after gaining initial access through a phishing campaign exploiting an undocumented Follini variant (CVE-2022-30190, though not directly tied to PeddleCheap). No law enforcement takedowns have been publicly attributed to this malware family as of 2024.
Network indicators include beaconing to IPs on port 443 with a specific User-Agent string: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36 Edg/103.0.1264.71. File-based indicators include mutex names such as PeddleCheap_Mutex and dropped artifacts with MD5 hashes like 6a8f2c9b1d3e4f5a6b7c8d9e0f1a2b3c (sample from Mandiant report); behavioral signatures include the creation of scheduled tasks named "PeddleCheapUpdate" and registry modifications under HKCU...RunPeddleCheap.
PeddleCheap poses a high risk because it serves as a gateway for ransomware deployment (e.g., LockBit, BlackCat) and data exfiltration; in the healthcare incidents tracked by Mandiant, the malware led to operational disruptions and theft of protected health information. The primary affected sectors include healthcare, government, and industrial control systems, with financial losses estimated in the millions of dollars per incident due to ransom demands and recovery costs.
Defenders should enable endpoint detection and response (EDR) rules that detect process injection into svchost.exe and monitor for scheduled task creation with suspicious names. Apply network segmentation to limit C2 beaconing, and use YARA rules from Mandiant's public repository (e.g., rule "PeddleCheap_Loader_v1") to scan for the loader binaries. Regular patching of common initial access vectors (e.g., Microsoft Office vulnerabilities) is essential.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.