PULSE NAME
PyPI Phishing Campaign | JuiceLedger Threat Actor Pivots From Fake Apps to Supply Chain Attacks - SentinelOne
WHITE eric.ford 2022-09-01 Modified: 2022-10-01
78
IOCs
HIGH VOLUME
A new threat actor focused on infostealing through a.NET assembly has launched a supply chain attack on open-source software PyPI, according to SentinelLabs and the PyPi Foundation.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
JuiceStealer August JuiceLedger Robux
Indicators of Compromise (9 / 78 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 3fc3dc88beff8ef77d2d48527ffa3d818eee885e9016a3ddf9affafa2f1e59c1 SHA256 of 8bbf55a78b6333ddb4c619d615099cc35dfeb4fb 2022-09-01
FileHash-SHA256 5e15f1e74512d51f5d51e8f4b16f60bbd349722eb689db3c8ab08ba04cc95b2e SHA256 of 55ba11f522532d105f68220db44392887952e57b 2022-09-01
FileHash-SHA256 60434af3ebe924efabc96558e6c8d8176bf4eb06dd6cc47b4c491da9964be874 SHA256 of 1e697bc7d6a9762bfec958ee278510583039579c 2022-09-01
FileHash-SHA256 643cc91bf12fc24d9d5995195060416273646c36c0bdf84a89f5e3867fde0afc SHA256 of cbc47435ccc62006310a130abd420c5fb4b278d2 2022-09-01
FileHash-SHA256 6b312c397001f666d725c9ae7dcbdb0712361e52304fddeb83f61ef03650baca SHA256 of 56e3421689d65e78ff75703dd6675956b86e09e8 2022-09-01
FileHash-SHA256 7586330732eec92214f594c5e6782cbb6f964f9c7db251e6c3b785a06c9d88bb SHA256 of 9fb18a3426efa0034f87dadffe06d490b105bda3 2022-09-01
FileHash-SHA256 8e97c6883e7af5cc1f88ac03197d62298906ac4a35a789d94cc9fde45ee7ea13 SHA256 of 5703ed6565888f0b06fffcc40030ba679936d29f 2022-09-01
FileHash-SHA256 a50bcbf0ef744f6b7780685cfd2f41a13be4c921d4b401384efd85c6109d7c00 SHA256 of 0a6731eba992c490d85d7a464fded2379996d77c 2022-09-01
FileHash-SHA256 c60ee99f05967085d47864208ca3e174275a01ebf0d5e3ea781e7216b41207d0 SHA256 of 567e1d5aa3a409a910631e109263d718ebd60506 2022-09-01