Fallout in python, Aug 31 – Sep 6

What we caught this week while monitoring over 163,052,840 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.

SUNDAY

Sun Sep 6 · 10 catches · 0 waves · 3 singles
objectives/credential-accesswell-knownwell-known/toolsmicro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/command-and-controlobjectivesobjectives/lateral-movementobjectives/privilege-escalation+8 17d
adpentest 1.2.0 python 17 days ago

Active Directory attack framework

delivery/wmiexploit/vulnerabilities
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildmicro-behaviors/cryptomicro-behaviors/datamicro-behaviors/osmicro-behaviors/dylibobjectives/anti-staticobjectivesobjectives/credential-access+4 17d

TikTok credential theft tool

encoding/layeredphishing/lure
well-knownwell-known/libmicro-behaviors/communicationsmicro-behaviorsobjectives/collectionmicro-behaviors/fsmicro-behaviors/datamicro-behaviors/osmicro-behaviors/processobjectivesobjectives/supply-chain 18d
mycord 1.2.5 python 18 days ago

Deletes local files via GitHub sync

hidden-payload/exec

SATURDAY

Sat Sep 5 · 5 catches · 0 waves · 3 singles
well-known/appwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/credential-accessobjectives/command-and-controlobjectivesthird-party+14 19d
dbabrain 0.7.0 python 19 days ago

RDP enable, sudoers NOPASSWD, masquerade, evasive base64

Powershell/Webdownloadcontrol/rdp
well-knownwell-known/toolsmicro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/lateral-movementobjectives/command-and-controlobjectives/credential-accessobjectivesthird_party+8 19d
adpentest 1.1.3 python 19 days ago

Active Directory attack framework

Impacket/impacketdump/system
objectives/credential-accesswell-knownwell-known/toolsmicro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/lateral-movementobjectivesobjectives/privilege-escalationthird-party+8 19d
adpentest 1.1.2 python 19 days ago

AD pentest framework, credential dumping

Impacket/impacketexploit/vulnerabilities

FRIDAY

Fri Sep 4 · 6 catches · 0 waves · 3 singles
well-knownwell-known/appmicro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/credential-accesswell-known/libwell-known/toolobjectivesobjectives/supply-chain+7 20d

Credential and AI-config exfiltration indicators

impersonation/core-module
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/osmicro-behaviors/processobjectivesobjectives/supply-chain 20d

Exfiltrates environment variables to remote server

credential-theft/package
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/importobjectives/executionobjectives/exfiltrationobjectives/credential-accessobjectives/discoveryobjectives/evasionobjectives/command-and-controlobjectives+9 20d
agaruda 1.0 python 20 days ago

Malicious hacking framework

reverse-shell/dupreverse-shell/socket-exec

THURSDAY

Thu Sep 3 · 4 catches · 0 waves · 3 singles
objectives/evasionmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/libobjectiveswell-knownwell-known/appobjectives/supply-chainthird_partymetadata/package+15 21d

Penetration testing attack toolkit

Iocs/Dec21app/package
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/command-and-controlobjectives/supply-chainmicro-behaviors/processmicro-behaviors/datamicro-behaviors/fsobjectives/anti-staticobjectives 21d
uvhttp-custom 1.7.9 python ✓ 21 days ago

obfuscated PowerShell dropper in setup.py

payload/encodedeval/scripting
well-knownwell-known/toolmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/credential-accessobjectives/lateral-movementobjectivesobjectives/privilege-escalationthird_party+6 21d
adpentest 1.1.0 python 21 days ago

Active Directory attack framework

Impacket/impacketexploit/vulnerabilities

WEDNESDAY

Wed Sep 2 · 5 catches · 0 waves · 3 singles
well-knownwell-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/discoveryobjectives/exfiltrationwell-known/toolsobjectivesobjectives/command-and-control+6 21d
ryry-cli 7.32 python 21 days ago

Remote task execution backdoor

tasking/command-polling
well-known/toolwell-knownmicro-behaviors/osmicro-behaviorsmetadata/packagemetadataobjectives/executionobjectives/credential-accessobjectives/command-and-controlobjectivesthird_party+17 21d
suijin 6.6.0 python 21 days ago

Autonomous offensive security tool

reverse-shell/dupDec21/Soft
well-knownwell-known/libmetadata/binarymetadataobjectives/anti-staticobjectives/discoveryobjectives/impactobjectives/evasionobjectivesmicro-behaviors/processmicro-behaviors+13 22d

Process injection and evasion APIs

injection/thread-hijackingransom/file-operations

MONDAY

Mon Aug 31 · 3 catches · 0 waves · 3 singles
well-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadatawell-known/libmicro-behaviors/dataobjectivesobjectives/impactwell-knownmicro-behaviors/ui+5 23d

Malicious SweetAlert2 payload targeting Russian users

supply-chain/sweetalert2-protestwaremanipulation/browser
micro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/anti-staticmicro-behaviors/datamicro-behaviors/dylibmicro-behaviors/hardwaremicro-behaviors/osobjectivesobjectives/command-and-control+1 24d
visppy 1.0.1 python 24 days ago

obfuscated payload, screen capture, rapid releases

staging/embedded
well-knownwell-known/libmicro-behaviors/communicationsmicro-behaviorsobjectives/evasionmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/datamicro-behaviors/processobjectivesobjectives/execution 24d

Remote code execution backdoor

cmd/injection
O objectives H behaviours Md metadata · a group subscript counts categories, an atom subscript subcategories