PIVOTPIPE: A New .NET Cobalt Strike-Compatible Payload
Score: 9/10

PIVOTPIPE: A New .NET Cobalt Strike-Compatible Payload

PIVOTPIPE is a newly discovered .NET malware that reimplements Cobalt Strike Beacon features with custom evasion techniques, including AMSI bypassing and indirect syscalls.

Executive Summary

In September 2026, IIJ identified a novel .NET-based malware dubbed PIVOTPIPE, hosted on an open directory. While the malware mimics the command structure and communication protocol of Cobalt Strike Beacons, it features distinct implementation logic for evasion and loading, suggesting it is an unofficial or independent reimplementation of the Beacon payload.

The attack chain involves a sophisticated .NET loader that performs several defense evasion maneuvers, including AMSI patching and sleep masking, before deploying a core RAT component. Analysis indicates the malware is likely in active development, as evidenced by hardcoded debug paths and artifacts found within the analyzed samples. PIVOTPIPE supports advanced P2P pivoting via SMB and TCP beacons, making it a significant threat for lateral movement within compromised networks.

Key Details

Threat Name

PIVOTPIPE

Affects

—

Adversary

—

Malware/Tools

PIVOTPIPE, Cobalt Strike, BlueShell, KimJongRAT, SLOTAGENT

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance9
Enterprise Relevance8
Clarity & Structure9
Technical Depth8

Sources