logo

PyLoose: Python-based fileless malware targets cloud workloads to deliver cryptominer

ID: f99aabe7-3817-5a8d-9ac5-1c25a15d48d8

STIX ID: report--f99aabe7-3817-5a8d-9ac5-1c25a15d48d8

Feed Name: Wiz Blog

Threat Score
65/100

Date Published: 2023-07-11

Date Updated: 2026-05-01

...
...

The report details “PyLoose,” a Python-based fileless cryptomining campaign that loads a precompiled XMRig miner directly into memory using Linux memfd (reflective execution) via exposed Jupyter Notebook services; it documents ~200 observed instances, provides full technical analysis of the loader and execution flow, lists IoCs (hashes, IPs, domains, wallet), maps MITRE techniques, and offers detection and mitigation guidance for cloud workloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.