logo

Code of Conduct: DPRK’s Python-fueled intrusions into secured networks

ID: 9ee20cc3-0435-54ae-a8fe-dd2819914276

STIX ID: report--9ee20cc3-0435-54ae-a8fe-dd2819914276

Feed Name: Elastic Security Labs

Threat Score
85/100

Date Published: 2024-09-18

Date Updated: 2026-04-27

...
...

This report analyzes a DPRK-associated initial-access campaign that uses socially engineered Python coding-challenge lures (RookeryCapital_PythonTest.zip / PasswordManager.py) which embed obfuscated Base64/ROT13 payloads. The malicious Pyperclip module writes a decoded Python script to the system temporary directory, executes it (platform-specific), and establishes C2 with a decoded URL (akamai...online) to receive and exec further commands, enabling remote code execution and potential data exfiltration; the report includes code-level dissection and detection/hunting recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.