logo

Twice around the dance floor - Elastic discovers the PIPEDANCE backdoor

ID: 471b7e40-49da-5a79-806e-f561edf8f8f0

STIX ID: report--471b7e40-49da-5a79-806e-f561edf8f8f0

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2023-02-27

Date Updated: 2026-04-27

...
...

Elastic Security Labs describes and analyzes PIPEDANCE, a previously undocumented Windows backdoor that uses hardcoded named pipes and RC4 to enable stealthy lateral movement, interactive shells, file/process discovery, multiple process-injection techniques (including Heaven’s Gate and thread hijacking), and network connectivity checks; the report includes command mappings, observed use to deploy Cobalt Strike in a Vietnamese environment, detection guidance (YARA, KQL), and IOCs such as SHA-256 hashes and a C2 URL.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.