PiTunnel
PiTunnel is a cloud-hosted remote-access service primarily aimed at Raspberry Pi devices (sister product of Dataplicity from Wildfoundry) that exposes local services and a persistent remote shell through the `*.pitunnel.com` tenant infrastructure. The agent installs via a curl|sudo bash one-liner (`curl -s https://pitunnel.com/get/<TOKEN> | sudo bash`) and supports persistent named tunnels via flags like `pitunnel --port=<PORT> --name=vnc --persist`. After install the operator can open arbitrary local TCP listeners (SSH, RDP, VNC, web) to the PiTunnel cloud for inbound interactive access without any firewall change on the victim host. Catalogued by the LOTTunnels project under the "shell access" category.
Tool overview
- Category
- RAT
- Research authors
- @MHaggis
- Created
- 2026-05-18
- Last modified
- 2026-09-22
- Privileges
- User or root (installer uses sudo, runtime can be user-level)
- Free / availability
- Yes (free + paid subscription)
- Verification required
- Tenant signup required; per-device install token embedded in installer URL
- Supported platforms
Linux
macOS
Capabilities
Executables & installation paths
- Filename
- pitunnel
- OriginalFileName
- pitunnel
- Description
- PiTunnel client binary; invokable as `pitunnel --port=<PORT> --name=<NAME> --persist` to register a persistent named tunnel back to the operator's tenant cloud.
Installation paths
FORENSIC EVIDENCE
Disk artifacts
- File
- /usr/local/bin/pitunnel
- Description
- PiTunnel client binary (default install path)
- OS
- Linux
- File
- /etc/systemd/system/pitunnel.service
- Description
- systemd unit file for PiTunnel persistence (created when `--persist` flag is used)
- OS
- Linux
FORENSIC EVIDENCE
Network artifacts
- Description
- PiTunnel control plane and per-tenant relay endpoints. Operator's named tunnels publish under `*.pitunnel.com` subdomains.
- Domains
- pitunnel.com
- www.pitunnel.com
- *.pitunnel.com
- Ports
- 443
FORENSIC EVIDENCE
Other artifacts
- Type
- URL
- Value
- https://pitunnel.com/get/<TOKEN>
- Type
- Other
- Value
- Install command: curl -s https://pitunnel.com/get/<TOKEN> | sudo bash (or wget -qO- ... | sudo bash) — high-signal hunt pattern (sudo-piped curl-to-bash from pitunnel.com)
- Type
- Other
- Value
- Persistent-tunnel command pattern: pitunnel --port=<PORT> --name=<NAME> --persist
- Type
- Other
- Value
- LOTTunnels project — Shell Access category: https://lottunnels.github.io/lottunnels/Binaries/pitunnel/
Detections
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/pitunnel_network_sigma.yml
- Description
- Detects potential network activity of PiTunnel RMM tool
References
Acknowledgements
- Person
- rcKillam
- Handle
- @rcKillam
- Person
- Michael Haag
- Handle
- @MHaggis