North Korea’s Post-Infection Python Payloads
2024-04-03 • Norfolk •
https://norfolkinfosec.com/north-koreas-post-infection-python-payloads/
A North Korean npm supply chain campaign used Python post-infection scripts against developers instead of relying only on malicious DLL delivery. The malicious Frontend.zip package retrieved an obfuscated main script that created a .n2 directory, then downloaded a browser stealer and a backdoor payload from actor-controlled infrastructure. The browser module targeted Chrome, Opera, Brave, and Yandex data on Windows, Linux, and macOS, while the payload collected host and geolocation details before connecting to a second C2. Supported commands covered process killing, shell execution, file upload, keylogger retrieval, document collection, AnyDesk installation, and re-fetching the browser stealer.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | ip-api.com | 2022-11-14 | 2026-01-21 |
| HASH | 8b2f2fad1d1f1e6ad915ea2224dd9f8… | 2024-04-03 | 2024-04-03 |
| HASH | 72400a957654371be9363fdd2753ffe… | 2024-04-03 | 2024-04-03 |
| HASH | ba47df4e0cccdff1c6e81b7a9e347ac… | 2024-04-03 | 2024-04-03 |