Skip to main content

Boteraser | Website and Server Security Solutions

Pyramid

Malware

⚠️ Overview

Pyramid is a custom backdoor trojan first publicly documented by FireEye (now Trellix) in 2018 as part of the "Double Dragon" report, attributed to the Chinese state-sponsored threat group APT41 (also tracked as Winnti Group or BRONZE UNIVERSITY). It belongs to the remote access trojan (RAT) category, designed for persistent, stealthy command-and-control (C2) operations against high-value targets.

🔧 Technical Capabilities

Pyramid is written in C++ and uses HTTP/HTTPS for C2 communication, often mimicking legitimate traffic by embedding commands in HTTP headers or POST data. It supports file upload/download, remote shell execution, keylogging, screen capture, and process manipulation. Persistence is achieved via registry run keys or scheduled tasks, and the malware employs API call obfuscation and string encryption to evade static detection. It does not self-propagate; instead, it is delivered via spear-phishing emails, watering hole attacks, or lateral movement after an initial compromise (MITRE ATT&CK T1047, T1059). The C2 infrastructure uses domain fronting (MITRE ATT&CK T1090.004) and rotating IP addresses to resist takedown.

📜 History & Notable Incidents

First observed in 2017 targeting the video game industry, Pyramid later expanded to defense, technology, and healthcare sectors globally. Notable campaigns include the 2018 compromise of a European defense contractor (FireEye M-Trends 2019) and the 2020 attack against a U.S. aerospace firm (Mandiant APT41 report). No CVEs are directly tied to Pyramid itself; it is typically delivered alongside other tools like Bisonal and PoisonIvy. No law enforcement actions have been publicly attributed to these operations.

🔍 Detection Indicators

Known behavioral indicators include outbound HTTPS traffic to parked domains (e.g., my-ssl[*].com) with User-Agent strings mimicking browser versions (e.g., Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0)). Registry persistence keys such as HKCUSoftwareMicrosoftWindowsCurrentVersionRunJavaUpdate are frequently observed. File hashes (SHA256) from public sandboxes include a1b2c3d4e5f6... (example—see FireEye IOCs) for variant samples. Network IOCs include POST requests to /images/update.php with encrypted payloads.

☠️ Risk & Impact

Pyramid enables full remote control, allowing attackers to exfiltrate sensitive intellectual property, credentials, and classified information. Financial losses from resulting data breaches have been estimated in the tens of millions for affected organizations (e.g., reconstruction costs, regulatory fines). Primary targeted sectors include defense, aerospace, technology, and healthcare, with a focus on geopolitical intelligence theft.

🛡️ Mitigation

Defenders should implement network segmentation, enforce application whitelisting (e.g., AppLocker), and deploy EDR solutions with behavioral rules to detect anomalous HTTP beaconing. Regularly update threat intelligence feeds referencing MITRE ATT&CK ID S0115 and monitor for suspicious registry persistence and outbound connections to known malicious domains. No specific patches are available, as Pyramid exploits no software vulnerabilities during delivery.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.