New ZiChatBot Malware Uses Zulip REST APIs as Command and Control Server
ID: 43357456-6c60-5ef7-b78c-c1f052659eb2
STIX ID: report--43357456-6c60-5ef7-b78c-c1f052659eb2
Feed Name: cybersecurityNews.com
Researchers discovered ZiChatBot, a cross-platform malware delivered via malicious PyPI packages that uses legitimate Zulip REST APIs as a covert command-and-control channel; the campaign (linked by dropper similarity to OceanLotus/APT32) employed deceptive package names and dependencies to install a dropper that deploys DLL/so payloads, establishes persistence, and retrieves shellcode, and researchers published multiple IoCs including filenames, hashes, a Zulip auth token, and a deactivated Zulip C2 domain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
