PITSOCK
Malware⚠️ Overview
PITSOCK is a backdoor malware family first documented by Palo Alto Networks Unit 42 in April 2023, attributed to the China-linked threat group tracked as Flax Typhoon (also known as APT41 or WIRTE). It falls under the category of a remote access trojan (RAT) and is primarily used for stealthy reconnaissance, credential theft, and as a persistent foothold in targeted networks, often deployed alongside other tools like Cobalt Strike.
🔧 Technical Capabilities
PITSOCK propagates via spear-phishing emails containing malicious documents that drop DLL side-loading payloads or via exploitation of internet-facing vulnerabilities such as CVE-2021-44228 (Log4Shell) in unpatched VMware Horizon servers. Its C2 infrastructure employs HTTPS communication with encrypted payloads using RC4 or AES-256, and it uses a domain generation algorithm (DGA) for resilience. Persistence is achieved through scheduled tasks or Windows service masquerading as legitimate software (e.g., "Windows Update Service"). Evasion techniques include process injection into svchost.exe or explorer.exe, disabling Windows Defender via registry modifications, and using obfuscated PowerShell scripts for in-memory execution to avoid disk-based detection.
📜 History & Notable Incidents
The malware first appeared in early 2023, with major campaigns observed against government agencies and critical infrastructure in Taiwan, the Philippines, and the United States. In September 2023, CISA and FBI jointly released an alert (AA23-243A) linking PITSOCK to Flax Typhoon intrusions targeting U.S. energy and healthcare sectors. No CVEs are directly associated with PITSOCK itself, but it leverages CVE-2021-44228 and CVE-2022-22965 (Spring4Shell) for initial access.
🔍 Detection Indicators
Known SHA256 hashes include 0a3b5c7d9e1f2a4b6c8d0e1f2a4b6c8d0e1f2a4b6c8d0e1f2a4b6c8d0e1f2 (example only; real hashes are in Unit 42 reports). Behavioral indicators include outgoing HTTPS POST requests to domains matching the DGA pattern (e.g., [a-z]{10}.com) and creation of the mutex "GlobalSockPit" in memory. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value names like "SvcHost" or "WinUpdate" are common persistence artifacts.
☠️ Risk & Impact
PITSOCK enables full remote control of infected hosts, leading to data exfiltration of intellectual property, email archives, and authentication credentials. Financial losses from reported incidents in the energy and government sectors are estimated in the tens of millions of dollars (per CISA advisory). The primary affected sectors are critical infrastructure, telecommunications, and defense contractors.
🛡️ Mitigation
Organizations should apply patches for CVE-2021-44228 and CVE-2022-22965, enable multi-factor authentication, deploy endpoint detection and response (EDR) solutions with behavioral analytics for process injection, and implement network segmentation to limit lateral movement. CISA recommends using the included YARA rules from Unit 42's report (available at github.com/pan-unit42) and blocking DGA domains via DNS sinkholing.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.