Gleaming Pisces Poisoned Python Packages Campaign Delivers PondRAT Linux and MacOS Backdoors
ID: 108e8814-9182-5c37-9605-10eb95575eb3
STIX ID: report--108e8814-9182-5c37-9605-10eb95575eb3
Feed Name: Palo Alto Networks Unit 42
Threat Score
Unit 42 analyzed a PyPI supply-chain campaign that distributed poisoned Python packages which installed Linux and macOS backdoors (PondRAT and variants of POOLRAT) and attributes the activity with medium confidence to North Korea–linked Gleaming Pisces based on shared code, function names, and a common encryption key; the report includes technical analysis, IOCs (file hashes and C2 domains), and detection/mitigation guidance for Palo Alto Networks customers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
