216.73.216.6

Analyzing Malicious Intent in Python Code: A Case Study

· Published 24/12/2024 02:29 · Modified 24/12/2024 13:17

Export JSON

Essential information

Published
24/12/2024 02:29
Modified
24/12/2024 13:17
Tags
2024-12-24 cometlogger-0.1 python zebo-0.1.0
Related entities
3 observables, 13 techniques (mitre)

Description

Two malicious packages, and , were identified by an AI-driven OSS malware detection system. These packages contain scripts designed for surveillance, data exfiltration, and unauthorized control. uses obfuscation techniques, keylogging, screen capturing, and data exfiltration to a remote server. It also implements a persistence mechanism to ensure re-execution upon system startup. exhibits webhook manipulation, information theft from various platforms, anti-VM detection, dynamic file modification, and persistence mechanisms. Both packages pose significant security risks, including credential leaks and sensitive information theft. The analysis highlights the importance of cybersecurity awareness and robust defensive measures against such malicious code.

External references