Labyrinth Chollima Using Poisoned Python Packages to Deliver PondRAT

2024-09-30 Poly Swarm

https://blog.polyswarm.io/labyrinth-chollima-using-poisoned-python-packages-to-deliver-pondrat

Thumbnail for Labyrinth Chollima Using Poisoned Python Packages to Deliver PondRAT

PolySwarm summarizes Unit 42 reporting on Labyrinth Chollima using poisoned Python packages on PyPI to deliver PondRAT to developer systems. The campaign targets software development supply chains by running an encoded next stage during package installation, retrieving the payload from C2, and executing Linux and macOS backdoors. PondRAT can upload and download files, check implant activity, sleep, and execute commands, while Unit 42 also identified a new Linux variant of PoolRAT. The attribution to Labyrinth Chollima rests on code and execution-flow similarities with AppleJeus-linked macOS malware and overlaps between PondRAT and PoolRAT.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 3c8dbfcbb4fccbaf924f9a650a04cb4… 2024-09-09 2024-12-27
HASH 0b5db31e47b0dccfdec46e74c0e70c6… 2024-09-09 2024-12-27
HASH 5c907b722c53a5be256dc5f96b755bc… 2024-09-09 2024-12-27
HASH bfd74b4a1b413fa785a49ca4a9c0594… 2024-09-09 2024-12-27
HASH f3b0da965a4050ab00fce727bb31e0f… 2024-09-09 2024-12-27

Related Actors

Related Reports

« Back