logo

Well-Established Cybercriminal Ecosystem Blooming in Iraq

ID: 7f7c9d81-37b7-5d29-abe6-abaf1c3139c6

STIX ID: report--7f7c9d81-37b7-5d29-abe6-abaf1c3139c6

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-07-15

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

Researchers discovered malicious Arabic-language Python packages on PyPI that include a script which scans user file systems (root and DCIM) for files (.py, .php, .zip) and images (.png, .jpg, .jpeg) and exfiltrates them to a hardcoded Telegram bot; analysis of the bot (≈90,000 messages) ties the activity to a broader Iraq-based cybercriminal ecosystem offering illicit services such as social media manipulation and financial theft tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.