PULSE NAME
Gleaming Pisces Poisoned Python Packages Campaign Delivers PondRAT Linux and macOS Backdoors
WHITE Gleaming Pisces AlienVault 2026-05-04 Modified: 2026-05-04
33
IOCs
MEDIUM VOLUME
An ongoing campaign has been discovered delivering Linux and macOS backdoors through poisoned Python packages uploaded to PyPI repository. The activity is attributed with medium confidence to Gleaming Pisces, a North Korean financially motivated threat actor affiliated with the Reconnaissance General Bureau. The campaign delivered PondRAT, identified as a lighter version of the known POOLRAT remote administration tool. Multiple malicious packages including real-ids, coloredtxt, beautifultext, and minisound were used to establish an evasive infection chain. The threat actor aims to compromise supply chain vendors through developer endpoints to ultimately access their customers' systems. Code analysis reveals significant similarities between PondRAT and previously attributed Gleaming Pisces malware, including identical function names, encryption keys, and execution flows. Both Linux and macOS variants were identified, demonstrating the group's expanding cross-platform capabilities targeting the cryptocurrenc...
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
PondRAT POOLRAT kupayupdate_stage2 BADCALL - S0245 AppleJeus - S0584
Indicators of Compromise (8 / 33 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 676537b0f7707feae0130bbcbdc881f5b4eb3f03 2026-05-04
FileHash-SHA1 6f391d282a37b770abcedd08c4c0e2156076cd8e 2026-05-04
FileHash-SHA1 720e6abf3befb585164450325246fe9cb000268f 2026-05-04
FileHash-SHA1 7637ee2925c88110fc15a77c120bf70dc66e84a7 2026-05-04
FileHash-SHA1 7b6e6487b803bbe85d7466b89da51a269fa4fc29 2026-05-04
FileHash-SHA1 8027c1d1ac0fd7d40ee850119c6d4501fbe75eab 2026-05-04
FileHash-SHA1 8a030a03570134cee4659b1b1f666f6f48c27fa5 2026-05-04
FileHash-SHA1 dd5bb0609b92163d8834a37a517885ce0b512938 2026-05-04