RAT

PiTunnel

PiTunnel is a cloud-hosted remote-access service primarily aimed at Raspberry Pi devices (sister product of Dataplicity from Wildfoundry) that exposes local services and a persistent remote shell through the `*.pitunnel.com` tenant infrastructure. The agent installs via a curl|sudo bash one-liner (`curl -s https://pitunnel.com/get/<TOKEN> | sudo bash`) and supports persistent named tunnels via flags like `pitunnel --port=<PORT> --name=vnc --persist`. After install the operator can open arbitrary local TCP listeners (SSH, RDP, VNC, web) to the PiTunnel cloud for inbound interactive access without any firewall change on the victim host. Catalogued by the LOTTunnels project under the "shell access" category.

Tool overview

Category
RAT
Research authors
@MHaggis
Created
2026-05-18
Last modified
2026-09-22
Privileges
User or root (installer uses sudo, runtime can be user-level)
Free / availability
Yes (free + paid subscription)
Verification required
Tenant signup required; per-device install token embedded in installer URL
Supported platforms
LinuxmacOS

Capabilities

Persistent named tunnels (`--persist` flag) that auto-reconnect on rebootTCP exposure of arbitrary local ports (SSH/RDP/VNC/HTTP) through the operator tenantCustom subdomain routing under `*.pitunnel.com`Custom Tunnels UI for non-CLI managementSister product to Dataplicity (same Wildfoundry-style cloud-relay architecture)

Executables & installation paths

Filename
pitunnel
OriginalFileName
pitunnel
Description
PiTunnel client binary; invokable as `pitunnel --port=<PORT> --name=<NAME> --persist` to register a persistent named tunnel back to the operator's tenant cloud.

Installation paths

/usr/local/bin/pitunnel
/opt/pitunnel/*
/etc/systemd/system/pitunnel.service

FORENSIC EVIDENCE

Disk artifacts

File
/usr/local/bin/pitunnel
Description
PiTunnel client binary (default install path)
OS
Linux
File
/etc/systemd/system/pitunnel.service
Description
systemd unit file for PiTunnel persistence (created when `--persist` flag is used)
OS
Linux

FORENSIC EVIDENCE

Network artifacts

Description
PiTunnel control plane and per-tenant relay endpoints. Operator's named tunnels publish under `*.pitunnel.com` subdomains.
Domains
  • pitunnel.com
  • www.pitunnel.com
  • *.pitunnel.com
Ports
  • 443

FORENSIC EVIDENCE

Other artifacts

Type
Other
Value
Install command: curl -s https://pitunnel.com/get/<TOKEN> | sudo bash (or wget -qO- ... | sudo bash) — high-signal hunt pattern (sudo-piped curl-to-bash from pitunnel.com)
Type
Other
Value
Persistent-tunnel command pattern: pitunnel --port=<PORT> --name=<NAME> --persist
Type
Other
Value
LOTTunnels project — Shell Access category: https://lottunnels.github.io/lottunnels/Binaries/pitunnel/

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/pitunnel_network_sigma.yml
Description
Detects potential network activity of PiTunnel RMM tool

References

Acknowledgements

Person
rcKillam
Handle
@rcKillam
Person
Michael Haag
Handle
@MHaggis