logo

New ZiChatBot Malware Uses Zulip REST APIs as Command and Control Server

ID: 43357456-6c60-5ef7-b78c-c1f052659eb2

STIX ID: report--43357456-6c60-5ef7-b78c-c1f052659eb2

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-05-08

Date Updated: 2026-05-11

Author: Tushar Subhra Dutta

...
...

Researchers discovered ZiChatBot, a cross-platform malware delivered via malicious PyPI packages that uses legitimate Zulip REST APIs as a covert command-and-control channel; the campaign (linked by dropper similarity to OceanLotus/APT32) employed deceptive package names and dependencies to install a dropper that deploys DLL/so payloads, establishes persistence, and retrieves shellcode, and researchers published multiple IoCs including filenames, hashes, a Zulip auth token, and a deactivated Zulip C2 domain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.