Executive Summary
In September 2026, IIJ identified a novel .NET-based malware dubbed PIVOTPIPE, hosted on an open directory. While the malware mimics the command structure and communication protocol of Cobalt Strike Beacons, it features distinct implementation logic for evasion and loading, suggesting it is an unofficial or independent reimplementation of the Beacon payload.
The attack chain involves a sophisticated .NET loader that performs several defense evasion maneuvers, including AMSI patching and sleep masking, before deploying a core RAT component. Analysis indicates the malware is likely in active development, as evidenced by hardcoded debug paths and artifacts found within the analyzed samples. PIVOTPIPE supports advanced P2P pivoting via SMB and TCP beacons, making it a significant threat for lateral movement within compromised networks.
