logo

Gleaming Pisces Poisoned Python Packages Campaign Delivers PondRAT Linux and MacOS Backdoors

ID: 108e8814-9182-5c37-9605-10eb95575eb3

STIX ID: report--108e8814-9182-5c37-9605-10eb95575eb3

Feed Name: Palo Alto Networks Unit 42

Threat Score
90/100

Date Published: 2024-09-18

Date Updated: 2026-04-28

Author: Yoav Zemah

...
...

Unit 42 analyzed a PyPI supply-chain campaign that distributed poisoned Python packages which installed Linux and macOS backdoors (PondRAT and variants of POOLRAT) and attributes the activity with medium confidence to North Korea–linked Gleaming Pisces based on shared code, function names, and a common encryption key; the report includes technical analysis, IOCs (file hashes and C2 domains), and detection/mitigation guidance for Palo Alto Networks customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.