Well-Established Cybercriminal Ecosystem Blooming in Iraq
ID: 7f7c9d81-37b7-5d29-abe6-abaf1c3139c6
STIX ID: report--7f7c9d81-37b7-5d29-abe6-abaf1c3139c6
Feed Name: Dark Reading
Date Published: 2024-07-15
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
Researchers discovered malicious Arabic-language Python packages on PyPI that include a script which scans user file systems (root and DCIM) for files (.py, .php, .zip) and images (.png, .jpg, .jpeg) and exfiltrates them to a hardcoded Telegram bot; analysis of the bot (≈90,000 messages) ties the activity to a broader Iraq-based cybercriminal ecosystem offering illicit services such as social media manipulation and financial theft tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
