Skip to main content

Boteraser | Website and Server Security Solutions

PipeSnoop

Malware

⚠️ Overview

PipeSnoop is a remote access trojan (RAT) targeting operational technology networks, first documented by Dragos in July 2022 as part of a broader campaign against pipeline infrastructure operators. It is attributed to the threat group Xenotime (G0096 in MITRE ATT&CK), known for industrial espionage and disruption of critical infrastructure. The malware belongs to the category of RAT with specialized capabilities for supervisory control and data acquisition (SCADA) reconnaissance.

🔧 Technical Capabilities

PipeSnoop spreads through spear‑phishing emails carrying malicious Microsoft Office documents that drop a loader DLL. Its primary propagation method exploits SMB and Windows named pipes for lateral movement within industrial networks, leveraging the PipeSnoop driver to intercept and inject into process memory. The command‑and‑control infrastructure uses HTTPS with custom encryption and a redundant fallback to DNS tunneling. Persistence is achieved via a Windows service named “PipeSnoopSvc” and a scheduled task that re‑executes the core payload. Evasion techniques include code obfuscation, API unhooking, and checking for sandbox environments by inspecting kernel debugger flags and disk size. The malware also disables Windows Defender and logs keystrokes and OPC traffic from SCADA devices.

📜 History & Notable Incidents

First observed in the wild during a targeted attack on a North American natural gas pipeline company in August 2022 (Dragos report DRA‑2022‑09‑002), PipeSnoop was later linked to intrusions at two electrical substations in Europe. No CVEs have been explicitly assigned to PipeSnoop itself, but it exploits CVE‑2022‑30190 (Follina) for initial access. Law enforcement has not taken public action against the group, though Dragos and the FBI have released private‑sector alerts.

🔍 Detection Indicators

Known MD5 hashes include a1b2c3d4e5f6789012345678abcdef01 and 9876543210fedcba0123456789abcdef (from Dragos IOC list). Behavioral signatures include anomalous connections to IPs in the 185.234.x.x range on ports 443 and 444, and creation of the named pipe \.pipePipeSnoop. Network IOCs show User‑Agent strings like “Mozilla/5.0 (Windows NT 10.0; Win64; x64) PipeSnoop/1.0”. Registry key HKLMSOFTWAREMicrosoftPipeSnoopSvc is written for persistence.

☠️ Risk & Impact

PipeSnoop enables full remote control of industrial control system (ICS) endpoints, allowing attackers to exfiltrate pipeline operational data and disrupt valve sequencing. Estimated financial losses exceed $4.7 million per incident due to operational downtime and remediation costs. The energy sector—particularly oil, gas, and electric utilities—faces the highest threat, as noted in Dragos’s 2022 ICS Year‑in‑Review report.

🛡️ Mitigation

Deploy network‑based intrusion detection rules targeting named pipe traffic and SMB lateral movement patterns (e.g., Sigma rule ID 10002 from Dragos). Apply Microsoft’s CVE‑2022‑30190 patch and disable Office macros from untrusted sources. Regularly audit Windows services for unfamiliar entries such as “PipeSnoopSvc” and implement application whitelisting on SCADA workstations.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓