Slow Pisces Targets Developers With Coding Challenges and Introduces New Customized Python Malware
ID: a9b98da9-62b7-588e-a3e0-20b512843586
STIX ID: report--a9b98da9-62b7-588e-a3e0-20b512843586
Feed Name: Palo Alto Networks Unit 42
Slow Pisces (aka Jade Sleet/TraderTraitor/PUKCHONG), a North Korean state-sponsored threat actor, targeted cryptocurrency developers by posing as recruiters and sending benign-looking coding challenges that fetch data from attacker-controlled C2 domains; the campaign uses YAML deserialization in Python and EJS escapeFunction in JavaScript to execute in-memory payloads (RN Loader and RN Stealer). The report provides a technical analysis of the infection chain, malware behavior, infrastructure timeline, a table of IoCs, and mitigation recommendations including device segregation and detection points.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
