DangerousPassword attacks targeting developers’ Windows, macOS, and Linux environments
ID: 4eba504b-ed62-580c-b198-866ebeecd672
STIX ID: report--4eba504b-ed62-580c-b198-866ebeecd672
Feed Name: JPCERT Blog
JPCERT/CC reports a targeted campaign by the DangerousPassword (aka CryptoMimic / SnatchCrypto) group that injects malicious code into developer libraries (a Python pyqrcode module and Node.js express files) to deploy downloader/backdoor malware across Windows, macOS, and Linux; the campaign uses obfuscation (ROT13/BASE64), scheduled execution, MSI-based droppers, DLL sideloading, and backdoors (PythonHTTPBackdoor, JokerSpy), and the report provides C2 domains and numerous malware hashes as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
