North Korea’s Post-Infection Python Payloads

2024-04-03 Norfolk

https://norfolkinfosec.com/north-koreas-post-infection-python-payloads/

Thumbnail for North Korea’s Post-Infection Python Payloads

A North Korean npm supply chain campaign used Python post-infection scripts against developers instead of relying only on malicious DLL delivery. The malicious Frontend.zip package retrieved an obfuscated main script that created a .n2 directory, then downloaded a browser stealer and a backdoor payload from actor-controlled infrastructure. The browser module targeted Chrome, Opera, Brave, and Yandex data on Windows, Linux, and macOS, while the payload collected host and geolocation details before connecting to a second C2. Supported commands covered process killing, shell execution, file upload, keylogger retrieval, document collection, AnyDesk installation, and re-fetching the browser stealer.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ip-api.com 2022-11-14 2026-01-21
HASH 8b2f2fad1d1f1e6ad915ea2224dd9f8… 2024-04-03 2024-04-03
HASH 72400a957654371be9363fdd2753ffe… 2024-04-03 2024-04-03
HASH ba47df4e0cccdff1c6e81b7a9e347ac… 2024-04-03 2024-04-03

Related Actors

Related Reports

« Back