ZiChatBot Malware Abuses Zulip APIs for Stealthy C2 Operations
ID: 83abf203-f25d-56af-93d8-bf7b58ae4ba6
STIX ID: report--83abf203-f25d-56af-93d8-bf7b58ae4ba6
Feed Name: GBHackers
A new cross‑platform malware family called ZiChatBot was distributed through malicious PyPI wheel packages (uuid32-utils, colorinal, termncolor). The packages drop platform‑specific droppers (terminate.dll/terminate.so) that decrypt and install payloads (vcpktsvr.exe/libcef.dll on Windows; /tmp/obsHub/obs-check-update on Linux), establish persistence (Run registry entry or cron job), and use Zulip public REST APIs as a stealthy C2 channel; analysis shows code overlap with OceanLotus and defenders are advised to block helper.zulipchat.com and search for listed artifacts and package names.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
