Loading...

11 Apr 2026 01:27

Tech & Start Up The Latest

Kaspersky uncovers PipeMagic backdoor attacks businesses in Saudi Arabia through fake ChatGPT application

Deploying a backdoor that both extracts sensitive data and enables full remote access to compromised devices

Kaspersky’s Global Research and Analysis Team (GReAT) has recently discovered a new malicious campaign involving the PipeMagic Trojan, which has shifted from targeting entities in Asia to expanding its reach to organizations in Saudi Arabia.

The attackers are using a fake ChatGPT application as bait, deploying a backdoor that both extracts sensitive data and enables full remote access to compromised devices. The malware also operates as a gateway, enabling the introduction of additional malware and the launch of further attacks across corporate network.

Kaspersky initially discovered PipeMagic backdoor in 2022, this plugin-based trojan was targeting entities in Asia at that time. The malware is capable of functioning as both a backdoor and a gateway. In September 2024, Kaspersky’s GReAT observed a resurgence of PipeMagic, this time targeting organizations in Saudi Arabia.

This version uses a fake ChatGPT application, built with the Rust programming language. At first glance, it appears legitimate, containing several common Rust libraries used in many other Rust-based applications. However, when executed, the application displays a blank screen with no visible interface and hides a 105,615-byte array of encrypted data which is a malicious payload.

In the second stage, the malware searches for key Windows API functions, by searching the corresponding memory offsets using names hashing algorithm. It then allocates memory, loads the PipeMagic backdoor, adjusts necessary settings, and executes the malware.

One of unique features of PipeMagic is that it generates a 16-byte random array to create a named pipe in the format \\.\pipe\1.<hex string>. It spawns a thread that continuously creates this pipe, reads data from it, and then destroys it. This pipe is used for receiving encoded payloads, stop signals via the default local interface. PipeMagic usually works with multiple plugins downloaded from a command-and-control (C2) server, which, in this case, was hosted on Microsoft Azure.

“Cybercriminals are constantly evolving their strategies to reach more prolific victims and broaden their presence, as demonstrated by the PipeMagic Trojan’s recent expansion from Asia to Saudi Arabia. Given its capabilities, we expect to see an increase in attacks leveraging this backdoor,’ comments Sergey Lozhkin, Principal Security Researcher at Kaspersky’s GReAT.

In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky researchers recommend implementing the following measures:

Be cautious when downloading software from the internet, especially if it’s from a third-party website. Always try to download software from the official website of the company or service that you are using.

Provide your SOC team with access to the latest threat intelligence (TI). Kaspersky Threat Intelligence is a single point of access for the company’s TI, providing it with cyberattack data and insights gathered by Kaspersky spanning over 20 years.

Upskill your cybersecurity team to tackle the latest targeted threats with Kaspersky online training developed by GReAT experts.

For endpoint level detection, investigation, and timely remediation of incidents, implement EDR solutions such as Kaspersky Next.

In addition to adopting essential endpoint protection, implement a corporate-grade security solution that detects advanced threats on the network level at an early stage, such as Kaspersky Anti Targeted Attack Platform.

As many targeted attacks start with phishing or other social engineering techniques, introduce security awareness training and teach practical skills to your team.

To gain exclusive insights into the latest APT campaigns and emerging trends in the threat landscape, register for the Security Analyst Summit here.

(Visited 65 times, 1 visits today)
peri hokiperihokiduta76duta 76ABC1131 - MPO SLOTABC1131 Bandar Slot Togelmix parlay agen slot qrisMPOGALAXYslot thailandAWSBEThttps://premium-soft.com/Consulta-Licencias/https://sintnicolaasschool.com/https://abc1131aa.com/kincir88Slot mahjongABC1131ABC1131 LOGINhttps://abc1131.hartanzah.com/https://www.abc1131.it.com/era77https://ayodonktolong.pages.dev/stc76sinkronisasi taktik jitu peluang dadu sicbo analisa rtp live gates of olympus strategi pola mahjong wild deluxe patenanatomi kemenangan mutlak taktik pola mahjong ways 2 pgsoft analisa strategi rtp live starlight princess teknik peluang baccaratpemetaan spektrum volatilitas strategi paten peluang blackjack teknik analisa rtp live sweet bonanza taktik pola mahjong wins 3 pragmaticmanajemen bantalan risiko gunakan teknik analisa peluang roulette taktik pola mahjong ways 2 pgsoft strategi rtp live wild west goldnavigasi kontras probabilitas teknik bagus taktik blackjack analisa peluang sv388 strategi pola mahjong wins 3 pragmatic rtp live sugar rushadaptasi kemenangan live casino taktik mahjong ways terbaru pastikan 5 lions megawaysadaptasi rtp live pastikan mahjong ways deluxe memecahkan gates of gatotkacadekonstruksi peluang roullete mampu tingkatkan rtp mahjong ways 2 tanpa sweet bonanza super scattereksplorasi teknik baccarat dengan pola fortune gods pastikan starlight archer 1000fakta terbaru dari dragon tiger mampu wild bounty showdown rtp live gates of olympus deluxeformula rtp live deluxe mahjong wins 3 dengan teknik baccarat tanpa pola aztec gemsmembaca rtp live sicbo algoritma mahjong wins menghasilkan fortune of olympuspenguasaan tanpa pola rtp live deluxe mahjong wins 2 lebih terpercaya starlight princess x1000rasio kemenangan sicbo saat rtp mahjong wins black scatter terbaru sweet bonanza superrasio lebih memilih dragon tiger saat mahjong black scatter menguasai starlight princessrasio lebih memilih roullete saat mahjong ways terpercaya rtp gates of olympus deluxestrategi memecahkan baccarat sesuai mahjong ways deluxe dengan teknik gates of olympusstrategi probabilitas mahjong ways 2 menggunakan baccarat deluxe pecahkan starlight princessstrategi ritme roullete memecahkan peluang mahjong ways 2 pastikan sweet bonanza xmasvoltalitas kemenangan sicbo berhasil capai puncak mahjong ways dengan gates of olympus x1000mekanika kemenangan teknik dadu sicbo analisa pola mahjong wild deluxe taktik rtp live gates of olympussinergi taruhan taktis analisa peluang baccarat teknik pola mahjong ways 2 pgsoft strategi rtp live starlight princessagresi taruhan terstruktur taktik peluang blackjack analisa pola mahjong wins 3 pragmatic teknik strategi rtp live sweet bonanzaeksekusi hibrida terkalkulasi taktik analisa peluang roulette strategi pola mahjong ways 2 pgsoft teknik rtp live wild west golde5 studi pola scatter dan wild dengan pendekatan algoritma moderne5 teknik analisis pola scatter dan wild berbasis algoritmae5 teknik spin efektif untuk mengoptimalkan performa rtpe5 teknik spin modern untuk hasil rtp lebih optimale5 terbongkar cara mengurai pola scatter dan wild dengan sistem algoritmae5 terbukti efektif teknik membaca scatter dan wild dengan sistem moderne5 teruji strategi algoritma ini bikin pola scatter dan wild lebih mudah dipahamie5 wajib tahu pola scatter dan wild bisa dibaca dengan pendekatan inimodulasi risiko algoritma teknik analisa peluang dadu sicbo strategi pola mahjong wild taktik rtp live olympusprotokol eksekusi hibrida analisa peluang baccarat teknik pola mahjong ways 2 taktik strategi rtp live starlight princessekspansi taruhan terukur analisa strategi rtp live sweet bonanza teknik pola mahjong wins 3 pragmatic taktik peluang sv388 blackjackaws interaksi lucky neko preferensi pemainaws momentum simbol mahjong scatter merahaws riset mahjong scatter emas tren rtpaws spin auto mahjong grid simbolaws symbol stutter multiplier olympusaws analisa putaran wild bandito otomatisasiaws analisis statistik simbol ekspektasi dataaws analogi spin otomatis putaran konsistenaws data spin rng pgsoftaws data starlight princess analisis scatteraws evaluasi rtp live data historisaws jeda spin mahjong wins bonusaws koi gate scatter tanpa polaaws pemetaan putaran pgsoft algoritmaaws rtp terbaru target logis pemainmahjong waystrik rahasia kemenanganpola baru mahjongstrategi amhjongstrategi unggul mahjongdragon tiger mahjong scatterrtp mahjong wins terbarumahjong wins tanpa polartp live mahjong winsformula mahjong wins 3strategi mahjong ways pg soft rahasia suhurahasia pg soft sensasi main mahjong ways 2visual manja mahjong ways terbaru animasicara baca simbol transisi mahjong ways 2rahasia dimensi waktu hasil mahjong wins 3pola mahjong agresif bonus besar tanpa hokistrategi mahjong agresif banjir bonus terbarurumus sakti mahjong ways 2 pola gacorbocoran eksklusif mahjong ways 2 indikator liveupdate analisis mahjong ways 2 waktu main Top