PULSE NAME
Attackers leverage PyPI to sideload malicious DLLs
WHITE AlienVault 2024-02-20 Modified: 2024-02-20
15
IOCs
MEDIUM VOLUME
ReversingLabs researchers discovered two malicious Python packages on PyPI that employed DLL sideloading to execute malicious payloads. Further investigation revealed connections to a larger campaign abusing open-source infrastructure.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Cobalt Strike - S0154
Indicators of Compromise (1 / 15 total)
All FileHash-MD5 FileHash-SHA1 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 e3214c81339540a3804fca656f5aea7d 2024-02-20