Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 22:36:35 UTC Home > List all groups > List all tools > List all groups using tool PupyRAT Tool: PupyRAT Names PupyRAT Pupy pupy Category Tools Type Backdoor Description Pupy is an open-source, cross-platform RAT and post-exploitation framework mainly written in python. Pupy can be loaded from various loaders, including PE EXE, reflective DLL, Linux ELF, pure python, powershell and APK. Most of the loaders bundle an embedded python runtime, python library modules in source/compiled/native forms as well as a flexible configuration. They bootstrap a python runtime environment mostly in-memory for the later stages of pupy to run in. Pupy can communicate using various transports, migrate into processes, load remote python code, python packages and python C-extensions from memory. Information MITRE ATT&CK Malpedia https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=7b6db856-4677-46f4-b422-1272cbb8c783 Page 1 of 2 Last change to this tool card: 22 April 2024 Download this tool card in JSON format All groups using tool PupyRAT Changed Name Country Observed APT groups   APT 33, Elfin, Magnallium 2013-Apr 2024     Cutting Kitten, TG-2889 2012-Mar 2016   LightBasin 2016     Magic Hound, APT 35, Cobalt Illusion, Charming Kitten 2012-Jun 2025 4 groups listed (4 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=7b6db856-4677-46f4-b422-1272cbb8c783 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=7b6db856-4677-46f4-b422-1272cbb8c783 Page 2 of 2