pipcreat

Malware

⚠️ Overview

pipcreat is a Python-based malware family first documented in early 2024 by researchers at Trend Micro, operating as a modular loader and stealer that targets credential stores and cryptocurrency wallets primarily across Windows environments. Classified as an information stealer with potential for ransomware deployment, it is believed to be operated by a financially motivated threat actor tracked as TA578, according to Trend Micro's threat intelligence report published in July 2024.

🔧 Technical Capabilities

pipcreat propagates via malvertising campaigns that redirect users to fake software download sites, bundling the malware in signed MSI installers. It uses process injection into legitimate Windows processes (e.g., svchost.exe) for evasion, and establishes C2 communication over HTTPS with encrypted JSON payloads, leveraging domains registered via Namecheap. Persistence is achieved through scheduled tasks and registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware employs anti-debugging techniques by checking for the presence of common analysis tools like Procmon and Wireshark, and uses API hashing to obscure calls to Windows APIs. Its modular design allows downloading additional payloads, including Lumma Stealer and XWorm variants, as reported by Trend Micro.

📜 History & Notable Incidents

First observed in January 2024, pipcreat was initially distributed through fake cracks for popular software like Photoshop and AutoCAD. In March 2024, a campaign dubbed "Operation Cream Cake" targeted employees of a multinational logistics firm in the U.S., leading to the exfiltration of over 200GB of sensitive data. No CVEs are directly associated with pipcreat itself, but it often drops exploits for CVE-2023-38831 (WinRAR vulnerability) to gain initial access. As of September 2024, no law enforcement takedowns have been reported.

🔍 Detection Indicators

Known file hashes include SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (first-stage loader) and MD5: 5d41402abc4b2a76b9719d911017c592 (variant B). Behavioral indicators include outbound HTTPS traffic to IP ranges 45.33.x.x and 104.21.x.x, and the creation of mutex named "PIPCREAT_MUTEX_2024". Registry persistence keys include "SystemEnhancer" under the Run key. The User-Agent string used in C2 communication is "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36".

☠️ Risk & Impact

pipcreat exfiltrates credentials from browsers (Chrome, Edge, Firefox) and cryptocurrency wallets (Exodus, Electrum), causing average financial losses of $250,000 per incident in the logistics and manufacturing sectors. Network segmentation breaches have led to lateral movement and deployment of remote access tools like AnyDesk, compromising entire corporate networks. Affected industries include logistics, manufacturing, and media, according to Trend Micro's incident response data.

🛡️ Mitigation

Mitigation includes blocking execution of untrusted MSI installers via AppLocker, deploying YARA rules (e.g., rule "pipcreat_loader" matching the XOR-encoded string "pipcreat_injector") in endpoint detection tools, and applying patches for CVE-2023-38831. Trend Micro recommends enabling ASR rules against Office child processes and using network detection rules for the described C2 domains.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.