PULSE NAME
Gleaming Pisces Poisoned Python Packages Campaign Delivers PondRAT Linux and macOS Backdoors
WHITE Gleaming Pisces AlienVault 2026-05-04 Modified: 2026-05-04
33
IOCs
MEDIUM VOLUME
An ongoing campaign has been discovered delivering Linux and macOS backdoors through poisoned Python packages uploaded to PyPI repository. The activity is attributed with medium confidence to Gleaming Pisces, a North Korean financially motivated threat actor affiliated with the Reconnaissance General Bureau. The campaign delivered PondRAT, identified as a lighter version of the known POOLRAT remote administration tool. Multiple malicious packages including real-ids, coloredtxt, beautifultext, and minisound were used to establish an evasive infection chain. The threat actor aims to compromise supply chain vendors through developer endpoints to ultimately access their customers' systems. Code analysis reveals significant similarities between PondRAT and previously attributed Gleaming Pisces malware, including identical function names, encryption keys, and execution flows. Both Linux and macOS variants were identified, demonstrating the group's expanding cross-platform capabilities targeting the cryptocurrenc...
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
PondRAT POOLRAT kupayupdate_stage2 BADCALL - S0245 AppleJeus - S0584
Indicators of Compromise (8 / 33 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 05957d98a75c04597649295dc846682d 2026-05-04
FileHash-MD5 33c9a47debdb07824c6c51e13740bdfe 2026-05-04
FileHash-MD5 4c66950d791ff5d39d53ffcd0b52a64d 2026-05-04
FileHash-MD5 61d7b2c7814971e5323ec67b3a3d7f45 2026-05-04
FileHash-MD5 6f2f61783a4a59449db4ba37211fa331 2026-05-04
FileHash-MD5 b62c912de846e743effdf7e5654a7605 2026-05-04
FileHash-MD5 ce35c935dcc9d55b2c79945bac77dc8e 2026-05-04
FileHash-MD5 f50c83a4147b86cdb20cc1fbae458865 2026-05-04