Termncolor and Colorinal Explained
ID: 09d197c8-c157-53f5-a840-0008b6ca0004
STIX ID: report--09d197c8-c157-53f5-a840-0008b6ca0004
Feed Name: Zscaler Security Research Blog
This analysis describes a malicious Python package chain where 'termncolor' pulls in a dependency 'colorinal' that contains unicode.py, which loads an embedded native library (terminate.dll / terminate.so) to decrypt and drop payloads into %LOCALAPPDATA%\vcpacket (including a signed vcpktsvr.exe and malicious libcef.dll), establish persistence via the HKCU Run key 'pkt-update', and communicate with a Zulip-based C2 to receive and execute shellcode; the report also documents a custom API-hashing routine, a Linux variant, and several file/registry indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
