Attackers leverage PyPI to sideload malicious DLLs
ID: 98b20e2a-56c3-52c7-a80a-1ed1b5ab9f03
STIX ID: report--98b20e2a-56c3-52c7-a80a-1ed1b5ab9f03
Feed Name: ReversingLabs Blog
ReversingLabs researchers discovered two typosquatted PyPI packages that perform DLL sideloading: the packages download a legitimate signed executable (ComServer.exe) and a malicious DLL (dgdeskband64.dll) which registers an exception handler, triggers an exception to transfer execution to downloaded shellcode (served as an .gif), and launches a Cobalt Strike Beacon; analysis links these packages to a broader campaign with additional DLL/EXE pairs and shared infrastructure, and the report provides technical details and IOCs for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
