logo

Attackers leverage PyPI to sideload malicious DLLs

ID: 98b20e2a-56c3-52c7-a80a-1ed1b5ab9f03

STIX ID: report--98b20e2a-56c3-52c7-a80a-1ed1b5ab9f03

Feed Name: ReversingLabs Blog

Threat Score
75/100

Date Published: 2024-02-20

Date Updated: 2026-04-29

Author: Petar Kirhmajer

...
...

ReversingLabs researchers discovered two typosquatted PyPI packages that perform DLL sideloading: the packages download a legitimate signed executable (ComServer.exe) and a malicious DLL (dgdeskband64.dll) which registers an exception handler, triggers an exception to transfer execution to downloaded shellcode (served as an .gif), and launches a Cobalt Strike Beacon; analysis links these packages to a broader campaign with additional DLL/EXE pairs and shared infrastructure, and the report provides technical details and IOCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.