PULSE NAME
Gleaming Pisces Poisoned Python Packages Campaign Delivers PondRAT Linux and MacOS Backdoors
WHITE Gleaming Pisces AlienVault 2024-09-19 Modified: 2024-09-19
38
IOCs
MEDIUM VOLUME
Unit 42 researchers have uncovered an ongoing campaign involving poisoned Python packages that deliver Linux and macOS backdoors. The attackers, believed to be the North Korean-affiliated group Gleaming Pisces, uploaded malicious packages to PyPI. The campaign's objective appears to be gaining access to supply chain vendors and their customers. The malware, named PondRAT, shares similarities with POOLRAT, a known tool in Gleaming Pisces' arsenal. The infection chain involves several stages of encoded code execution, ultimately downloading and running the RAT. Similarities in code structure, function names, and encryption keys between PondRAT and previously attributed malware strengthen the connection to Gleaming Pisces. The research also revealed Linux variants of POOLRAT, expanding the group's cross-platform capabilities.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
PondRAT POOLRAT AppleJeus - S0584
Indicators of Compromise (10 / 38 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 05957d98a75c04597649295dc846682d 2024-09-19
FileHash-MD5 17ab2927a235a0b98480945285767bcf 2024-09-19
FileHash-MD5 33c9a47debdb07824c6c51e13740bdfe 2024-09-19
FileHash-MD5 451c23709ecd5a8461ad060f6346930c 2024-09-19
FileHash-MD5 4c66950d791ff5d39d53ffcd0b52a64d 2024-09-19
FileHash-MD5 61d7b2c7814971e5323ec67b3a3d7f45 2024-09-19
FileHash-MD5 6f2f61783a4a59449db4ba37211fa331 2024-09-19
FileHash-MD5 b62c912de846e743effdf7e5654a7605 2024-09-19
FileHash-MD5 ce35c935dcc9d55b2c79945bac77dc8e 2024-09-19
FileHash-MD5 f50c83a4147b86cdb20cc1fbae458865 2024-09-19