Loading...

02 May 2026 10:54

Tech & Start Up The Latest

Kaspersky uncovers PipeMagic backdoor attacks businesses in Saudi Arabia through fake ChatGPT application

Deploying a backdoor that both extracts sensitive data and enables full remote access to compromised devices

Kaspersky’s Global Research and Analysis Team (GReAT) has recently discovered a new malicious campaign involving the PipeMagic Trojan, which has shifted from targeting entities in Asia to expanding its reach to organizations in Saudi Arabia.

The attackers are using a fake ChatGPT application as bait, deploying a backdoor that both extracts sensitive data and enables full remote access to compromised devices. The malware also operates as a gateway, enabling the introduction of additional malware and the launch of further attacks across corporate network.

Kaspersky initially discovered PipeMagic backdoor in 2022, this plugin-based trojan was targeting entities in Asia at that time. The malware is capable of functioning as both a backdoor and a gateway. In September 2024, Kaspersky’s GReAT observed a resurgence of PipeMagic, this time targeting organizations in Saudi Arabia.

This version uses a fake ChatGPT application, built with the Rust programming language. At first glance, it appears legitimate, containing several common Rust libraries used in many other Rust-based applications. However, when executed, the application displays a blank screen with no visible interface and hides a 105,615-byte array of encrypted data which is a malicious payload.

In the second stage, the malware searches for key Windows API functions, by searching the corresponding memory offsets using names hashing algorithm. It then allocates memory, loads the PipeMagic backdoor, adjusts necessary settings, and executes the malware.

One of unique features of PipeMagic is that it generates a 16-byte random array to create a named pipe in the format \\.\pipe\1.<hex string>. It spawns a thread that continuously creates this pipe, reads data from it, and then destroys it. This pipe is used for receiving encoded payloads, stop signals via the default local interface. PipeMagic usually works with multiple plugins downloaded from a command-and-control (C2) server, which, in this case, was hosted on Microsoft Azure.

“Cybercriminals are constantly evolving their strategies to reach more prolific victims and broaden their presence, as demonstrated by the PipeMagic Trojan’s recent expansion from Asia to Saudi Arabia. Given its capabilities, we expect to see an increase in attacks leveraging this backdoor,’ comments Sergey Lozhkin, Principal Security Researcher at Kaspersky’s GReAT.

In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky researchers recommend implementing the following measures:

Be cautious when downloading software from the internet, especially if it’s from a third-party website. Always try to download software from the official website of the company or service that you are using.

Provide your SOC team with access to the latest threat intelligence (TI). Kaspersky Threat Intelligence is a single point of access for the company’s TI, providing it with cyberattack data and insights gathered by Kaspersky spanning over 20 years.

Upskill your cybersecurity team to tackle the latest targeted threats with Kaspersky online training developed by GReAT experts.

For endpoint level detection, investigation, and timely remediation of incidents, implement EDR solutions such as Kaspersky Next.

In addition to adopting essential endpoint protection, implement a corporate-grade security solution that detects advanced threats on the network level at an early stage, such as Kaspersky Anti Targeted Attack Platform.

As many targeted attacks start with phishing or other social engineering techniques, introduce security awareness training and teach practical skills to your team.

To gain exclusive insights into the latest APT campaigns and emerging trends in the threat landscape, register for the Security Analyst Summit here.

(Visited 68 times, 1 visits today)
peri hokiperihokiduta76duta 76ABC1131 - MPO SLOTABC1131 Bandar Slot Togelmix parlay agen slot qrisMPOGALAXYslot thailandAWSBEThttps://premium-soft.com/Consulta-Licencias/https://sintnicolaasschool.com/https://abc1131aa.com/kincir88cakar76Slot mahjongABC1131ABC1131 LOGINhttps://abc1131.hartanzah.com/https://www.abc1131.it.com/stc76006 sinkronisasi momentum strategi hibrida pola scatter mahjong wild deluxe gates of olympus manajemen risiko dadu sicbo007 rekayasa taktik hibrida pola transformasi gold simbol mahjong ways 2 pgsoft baccarat prediksi starlight princess008 arsitektur kemenangan terpadu navigasi strategi blackjack optimasi peluang sweet bonanza mahjong wins 3 pragmatic009 dekonstruksi momentum strategi eksploitasi pola scatter mahjong ways 2 pgsoft teknik unit roulette wild west gold010 manifesto ekspertis navigasi rtp live sugar rush pola statis sv388 taktik kalkulasi blackjack mahjong wins 3 pragmatic011 rekayasa taktik lintas platform optimasi teknik analisa statistik mahjong wild deluxe gates of olympus dadu sicbo012 sinkronisasi data teknik rtp live mahjong ways 2 pgoft strategi baccarat statis dan dinamis starlight princess013 sinergi operasional integrasi teknik analisa statis blackjack dinamika sweet bonanza mahjong wins 3 pragmatic014 manifesto ekspertis rekayasa peluang algoritma pgsoft mahjong ways 2 pgsoft dinamika roulette wild west gold015 protokol strategis optimasi teknik analisa mahjong wins 3 pragmatic sugar rush sv388 blackjack proeksekusi taktik analisa pola gates of olympus dadu sicbo mahjong wild deluxetaktik peluang baccarat teknik analisa pola rtp live starlight princess mahjong ways 2 pgsoftsinergi strategi analisa peluang blackjack taktik teknik pola rtp live mahjong wins 3 pragmatic sweet bonanzaanalisa teknik peluang roulette taktik pola strategi rtp live mahjong ways 2 pgsoft wild west goldstrategi peluang blackjack analisa sv388 teknik taktik pola rtp live mahjong wins 3 pragmatic sugar rushpola mahjong ways 2 spin manualmanajemen saldo olympus 1000jam gacor pragmatic vs pg softfitur baru pg soft 2026mekanik baru pragmatic playmitos rtp live slot onlinegame pg soft low volatilityefek spin turbo algoritma slotrahasia frame emas wild banditoreview fitur buy spin pragmaticintegrasi analisa pola taktik rtp live strategi mahjong wild deluxe dadu sicbo gates of olympusmetodologi strategi teknik rtp live analisa pola mahjong ways 2 pgsoft baccarat starlight princessrekayasa metodologi peluang blackjack pola mahjong wins 3 pragmatic teknik sweet bonanzakomputasi peluang analisa strategi roulette pola mahjong ways 2 pgsoft taktik wild west goldmetodologi taktik presisi peluang blackjack pola sugar rush analisa sv388 mahjong wins 3 pragmaticmengindustrialisai perkembangan teknologi digital mahjong wins menuju kebebasan invoasi modernrevolusi industri digital mahjong ways dengan sistem integrasi ai merevolusionerkan peradabanstrategi tepat cuan mahjong ways 2 menurut mahjong analis era transformasi digitalteknologi cloud mahjong wins 3 bikin performa permainan terasa lebih stabiltransformasional teknologi digital mendorong kerangka mahjong ways 2 dengan pola dan rtp roboticlogika win streak pg softpenjelasan ilmiah scatter hitampotensi maxwin game sederhanarahasia near miss jackpotfakta menang akun barupeluang multiplier x500 olympusalgoritma scatter setelah maintenanceefek sering ganti game pg softtanda algoritma sedang downfungsi fitur double chanceanalisa lintas algoritma sinkronisasi pola mahjong wild deluxe gates of olympus probabilitas dadu sicboarsitektur strategi hybrid integrasi taktik baccarat pola presisi mahjong ways 2 pgsoft starlight princessprotokol rtp live integrasi strategi blackjack volatilitas mahjong wins 3 pragmatic sweet bonanzadialektika probabilitas analisa pola mahjong ways 2 pgsoft integrasi strategi roulette wild west goldrekayasa peluang membedah strategi mahjong wins 3 pragmatic sugar rush kalkulasi taktis sv388kesempatan emas mahjong ways hadir dalam sesi game online terbaikkilas balik penggunaan mahjong ways yang mulai terlihat di digital onlinekomposisi gaya pola mahjong ways 2 mengoptimalkan rtp live deluxemembaca gaya permainan tanpa pola mahjong ways disesuaikan poker onlinemomen mahjong ways mencapai puncak tertinggi tanpa menggunakan pola gates of olympusobservasi taktik dan gaya permainan terbaru yang dimiliki lucky nekorasio peningkatan taktik mahjong ways semakin terlihat di pg softstrategi mahjong ways untuk terjun di permainan online semakin meningkatkan di tahun 2026struktur permainan mahjong ways dengan penilaian casino onlinestudi banding teknik wild bounty showdown pastikan roulette alami peningkatan Top