logo

ZiChatBot Malware Abuses Zulip APIs for Stealthy C2 Operations

ID: 83abf203-f25d-56af-93d8-bf7b58ae4ba6

STIX ID: report--83abf203-f25d-56af-93d8-bf7b58ae4ba6

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Mayura Kathir

...
...

A new cross‑platform malware family called ZiChatBot was distributed through malicious PyPI wheel packages (uuid32-utils, colorinal, termncolor). The packages drop platform‑specific droppers (terminate.dll/terminate.so) that decrypt and install payloads (vcpktsvr.exe/libcef.dll on Windows; /tmp/obsHub/obs-check-update on Linux), establish persistence (Run registry entry or cron job), and use Zulip public REST APIs as a stealthy C2 channel; analysis shows code overlap with OceanLotus and defenders are advised to block helper.zulipchat.com and search for listed artifacts and package names.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.