[ << ALL_FEED ]

Malware in open source!

More in General

Mmaallwwaarree iinn ooppeennssoouurrccee!

A notable campaign by a single researcher is unfolding online. The following packages belong to him:

User lastbright:
🟢yyttt
🟢bbllaacckkwwoollff
🟢bbllaacckkwwoollff-6ad8f762-1a91-45d7-a9c5-356bd858356a
🟢bbllaacckkwwoollff6ad8f762
🟢bbllaacckkwwoollff6ad8f751
🟢bbllaacckkwwoollff6ad8f752
🟢bbllaacckkwwoollff6ad8f753
User lifeyi2253:
🟢f2d5cfdc642c3d4
🟢f2d5cfdc642c3d5

The payload triggers at the moment of package installation.

It is interesting to watch in real time how the campaign develops:

🔤 PoC with comments in Chinese. An LLM assistant likely had a hand in this (screenshot 1, library yyttt 0.1).

🔤 The output of the Unix command id is sent to a remote server (screenshot 2, bbllaacckkwwoollff 0.1, 0.2).

🔤 Code received from a C2 server is executed (screenshot 3, bbllaacckkwwoollff 0.3, 0.4, bbllaacckkwwoollff-6ad8f762-1a91-45d7-a9c5-356bd858356a 0.1).

🔤 Why not grab a listing of interesting directories (/opt/, /run/), environment variables, and other goodies (screenshot 4, bbllaacckkwwoollff6ad8f753 0.1)?

🔤 No, that’s too much, /etc/ is enough from the directories (screenshot 5, f2d5cfdc642c3d5 0.1).

On the host or on a test virtual machine, the attacker uses the username mind, as indicated by the path /home/mind/configuration/config.py in the fourth iteration (screenshot 4).

The package naming convention is noteworthy. Besides, it is always interesting to follow in real time how the attacker struggles with his packages being removed via reports 😈

In information security there is a term “The Pyramid of Pain” — it describes the difficulty of evading detection. So, within the campaign, the attacker uses the same unique file __init__.py, shown in screenshot 6. The PT PyAnalysis system easily highlights this 😑

Beware of all sorts of wolves.

#ti #scs #pyanalysis
@ptescalator

More from ti_author

More from ti_author

More in General