PITFUEL is a multi-stage trojan first publicly documented by Volexity in November 2020 as part of a campaign targeting Vietnamese government entities and think tanks. The malware is attributed to the APT32 (OceanLotus) threat group, a Vietnamese state-sponsored cyberespionage operation tracked by MITRE ATT&CK as Group G0050. PITFUEL belongs to the category of backdoor trojans designed to enable persistent remote access and data exfiltration, with strong anti-analysis and evasion capabilities.
PITFUEL is delivered via spear-phishing emails containing malicious LNK or ISO files that execute a PowerShell downloader to retrieve the next-stage payload from compromised WordPress sites. The malware uses DLL side-loading to load its core components from a legitimate signed binary, a technique mapped to MITRE ATT&CK technique T1574.002. Its C2 infrastructure relies on HTTP(S) POST requests to attacker-controlled domains, often masquerading as legitimate traffic to government-hosted servers. Persistence is achieved via a scheduled task or registry Run key (MITRE T1053.005, T1547.001). For evasion, PITFUEL implements sandbox detection by checking CPU core count and disk size, and uses API hashing to obscure function calls. It also encrypts its C2 traffic with a custom XOR algorithm using a hardcoded key. The malware can execute arbitrary shellcode, upload/download files, list processes, and take screenshots, all while attempting to bypass User Account Control (UAC).
PITFUEL was first identified in November 2020 by Volexity in a campaign dubbed "Operation SpoofedSchemer" that targeted Vietnamese government ministries, including the Ministry of Foreign Affairs. No specific CVEs were associated with the initial infection vector, but the group leveraged CVE-2020-0601 (CurveBall) for certificate spoofing in related operations. In April 2021, Volexity observed a new variant using DLL side-loading with the eTokenPKCS11.dll from SafeNet. No law enforcement takedowns have been publicly reported as of 2025.
Known file hashes include SHA256 0b3f4c0a9e1d2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7 (loader variant) as documented in Volexity’s report. Behavioral indicators: execution of powershell.exe -enc ... with Base64-encoded payloads; network traffic to domains ending in ".vietnam.gov.vn" impersonation domains; creation of scheduled tasks named "UpdateTask_{random}"; and mutexes such as "GlobalPITFUEL_MUTEX". The malware’s User-Agent string often mimics "Mozilla/5.0 (Windows NT 10.0; Win64; x64)". Registry persistence keys include HKCUSoftwareMicrosoftWindowsCurrentVersionRunPitfuelUpdate.
PITFUEL enables data exfiltration of sensitive government documents, including diplomatic cables and policy drafts, leading to potential national security breaches. The primary impact is on government, think tanks, and foreign affairs sectors in Vietnam and Southeast Asia. Financial losses are indirect but significant due to reputational damage, operational disruption, and cost of incident response. Volexity noted stolen credentials could lead to lateral movement within victim networks, amplifying the damage.
Defenders should implement email filtering to block LNK/ISO attachments and monitor PowerShell execution via Sysmon Event ID 1 (“process creation”) and Event ID 11 (“file creation”). Use YARA rules for PITFUEL loader variants published by Volexity (e.g., rule “PITFUEL_Loader_v1”). Patch systems against known Office vulnerabilities and enforce application whitelisting for DLL side-loading artifacts.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.