DangerousPassword attacks targeting developers’ Windows, macOS, and Linux environments

2023-07-19 JPCERT

https://blogs.jpcert.or.jp/en/2023/07/dangerouspassword_dev.html

Thumbnail for DangerousPassword attacks targeting developers’ Windows, macOS, and Linux environments

The DangerousPassword/CryptoMimic activity described by JPCERT/CC targeted cryptocurrency-exchange developers across Windows, macOS, and Linux systems with tampered Python and Node.js components. The Python path inserted malicious code into pyqrcode's builder.py, used ROT13- and Base64-obfuscated C2 data, downloaded MSI payloads on Windows, and executed a Python downloader on macOS/Linux that polled C2 and ran returned code. Follow-on payloads included devobj.dll sideloaded through rdpclip.exe, PythonHTTPBackdoor with OS-specific command execution and download functions, and possible JokerSpy samples for macOS. The Node.js path modified express route.js and used request.js to download server.js from C2, reinforcing that the campaign was built around developer tooling and git-themed artifacts.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 6d3eff4e029db9d7b8dc076cfed5e23… 2023-07-12 2024-04-11
HASH 39bbc16028fd46bf4ddad49c2143950… 2023-07-12 2023-07-19
HASH a7b0fa9c724e7837da97dc9c48ba76b… 2023-07-12 2023-07-19
HASH 56c6ab0083cf7edae7491e9c49b0cd9… 2023-07-12 2023-07-19
HASH 951039bf66cdf436c240ef206ef7356… 2023-07-12 2023-07-19
HASH 1599f7365db421e4fe07a169309624e… 2023-07-12 2023-07-19
HASH 84bfc8c5bdba5b4eaa885af5e698382… 2023-07-12 2023-07-19
HASH 118c1187c5b37ab9c4f9f39500d777c… 2023-07-12 2023-07-19
HASH 528ac7bdd56a6e7ff515c6e0936db66… 2023-07-12 2023-07-19
HASH 2eea41eefdc11f9fb7607fc4ef90f76… 2023-07-12 2023-07-19
HASH 37850b6a422479e95e9fb856f3541a3… 2023-07-12 2023-07-19
HASH 575e852a1f24e84dacec9892042f2d2… 2023-07-12 2023-07-19
HASH 5fe1790667ee5085e73b054566d548e… 2023-07-12 2023-07-19
HASH 67a0f25a20954a353021bbdfdd531f7… 2023-07-12 2023-07-19
HASH 35b4550050748c54faad1e5883c281f… 2023-07-12 2023-07-19
HASH e0891a1bfa5980171599dc5fe31d15b… 2023-07-12 2023-07-19
HASH 474c8a5ba3614cca1c48f34df73bfad… 2023-07-12 2023-07-19
DOMAIN checkdevinc.com 2023-07-12 2023-07-19
DOMAIN app.developcore.org 2023-07-12 2023-07-19
HASH aa951c053baf011d08f3a60a10c1d09… 2023-06-21 2023-07-19
HASH d895075057e491b34b0f8c0392b44e4… 2023-06-21 2023-07-19

Related Reports

« Back