New Malicious PyPI Packages used by Lazarus
ID: b9491312-6e87-54be-ae1b-1a050eecd93a
STIX ID: report--b9491312-6e87-54be-ae1b-1a050eecd93a
Feed Name: JPCERT Blog
Threat Score
JPCERT/CC confirms that the Lazarus APT published multiple malicious Python packages on PyPI (pycryptoenv, pycryptoconf, quasarlib, swapmempool) using typosquatting to distribute Comebacker malware; the packages contain XOR-encoded DLLs decoded and executed via rundll32, with network C2 POST behavior, listed C2 domains/IPs, file hashes, and PDBs provided as IOCs for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
