Labyrinth Chollima Using Poisoned Python Packages to Deliver PondRAT
2024-09-30 • Poly Swarm •
https://blog.polyswarm.io/labyrinth-chollima-using-poisoned-python-packages-to-deliver-pondrat
PolySwarm summarizes Unit 42 reporting on Labyrinth Chollima using poisoned Python packages on PyPI to deliver PondRAT to developer systems. The campaign targets software development supply chains by running an encoded next stage during package installation, retrieving the payload from C2, and executing Linux and macOS backdoors. PondRAT can upload and download files, check implant activity, sleep, and execute commands, while Unit 42 also identified a new Linux variant of PoolRAT. The attribution to Labyrinth Chollima rests on code and execution-flow similarities with AppleJeus-linked macOS malware and overlaps between PondRAT and PoolRAT.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 3c8dbfcbb4fccbaf924f9a650a04cb4… | 2024-09-09 | 2024-12-27 |
| HASH | 0b5db31e47b0dccfdec46e74c0e70c6… | 2024-09-09 | 2024-12-27 |
| HASH | 5c907b722c53a5be256dc5f96b755bc… | 2024-09-09 | 2024-12-27 |
| HASH | bfd74b4a1b413fa785a49ca4a9c0594… | 2024-09-09 | 2024-12-27 |
| HASH | f3b0da965a4050ab00fce727bb31e0f… | 2024-09-09 | 2024-12-27 |