RAT

Dataplicity

Dataplicity (by Wildfoundry) is a cloud-hosted remote-access service that exposes Linux systems — primarily Raspberry Pi devices — to the Dataplicity cloud for browser-based remote shell, "Wormhole" HTTP tunneling, and remote management. The agent installs via a curl|sudo python one-liner (`curl -s https://www.dataplicity.com/<TOKEN>.py | sudo python`) and registers the host with the operator's tenant under `*.dataplicity.com`. After install the operator has persistent remote shell access through the Dataplicity web console or Windows companion app without any inbound firewall change on the victim host. Catalogued by the LOTTunnels project under the "shell access" category for exactly this abuse profile.

Tool overview

Category
RAT
Research authors
@MHaggis
Created
2026-05-18
Last modified
2026-09-22
Privileges
root (Linux installer uses sudo)
Free / availability
Yes (free + paid tiers)
Verification required
Tenant signup required; per-device install token embedded in installer URL
Supported platforms
LinuxWindowsmacOS

Capabilities

Browser-based remote terminal (shell access through Dataplicity web console)Wormhole HTTP tunneling (expose a local HTTP service publicly via `*.wormhole.dataplicity.com`)Remote file managementPersistent device registration in operator tenantWindows desktop companion app for managing connected devices

Executables & installation paths

Filename
dataplicity
OriginalFileName
dataplicity
Description
Dataplicity agent (Python-based) installed via curl|sudo python one-liner; runs as a system service that maintains the persistent control channel back to *.dataplicity.com.

Installation paths

/opt/dataplicity/*
/opt/dataplicity/tuxtunnel/*
/usr/local/bin/dataplicity
/etc/systemd/system/dataplicity.service
/etc/init.d/dataplicity

FORENSIC EVIDENCE

Disk artifacts

File
/opt/dataplicity/tuxtunnel/manager
Description
Dataplicity manager binary (the persistent remote-control daemon)
OS
Linux
File
/opt/dataplicity/credentials
Description
Dataplicity agent credentials file (per-tenant install token + device identity)
OS
Linux
File
/etc/systemd/system/dataplicity.service
Description
systemd unit file for Dataplicity agent persistence
OS
Linux
File
/etc/init.d/dataplicity
Description
SysV init script for Dataplicity agent persistence (older or non-systemd Linux distributions)
OS
Linux

FORENSIC EVIDENCE

Network artifacts

Description
Dataplicity control plane and per-device tenant subdomain. Each registered device gets a `*.dataplicity.com` URL the operator uses to open a browser-based shell. `*.wormhole.dataplicity.com` is the HTTP-tunnel subdomain used to publish local HTTP services.
Domains
  • dataplicity.com
  • www.dataplicity.com
  • *.dataplicity.com
  • *.wormhole.dataplicity.com
Ports
  • 443

FORENSIC EVIDENCE

Other artifacts

Type
Other
Value
Install command: curl -s https://www.dataplicity.com/<TOKEN>.py | sudo python (high-signal hunt pattern — sudo-piped curl-to-python from dataplicity.com)
Type
Other
Value
LOTTunnels project — Shell Access category: https://lottunnels.github.io/lottunnels/Binaries/dataplicity/

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/dataplicity_network_sigma.yml
Description
Detects potential network activity of Dataplicity RMM tool

References

Acknowledgements

Person
rcKillam
Handle
@rcKillam
Person
Michael Haag
Handle
@MHaggis