TF-MAL-osx.poolrat
📛 Threat Title
Malware family: POOLRAT
Description
ThreatFox malware family `osx.poolrat`. Printable name: POOLRAT. Aliases: SIMPLESEA,SIMPLETEA.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.poolrat
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.poolrat
IOC database
- Type
- domain
- Value
osx.poolrat- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.poolrat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.poolrat
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as POOLRAT .
-
web:cyberpress.org
Researchers have identified a new malware campaign targeting supply chains through poisoned Python packages. The malicious software, dubbed PondRAT, is a lightweight version of the previously known POOLRAT RAT. Attackers uploaded these infected packages to the PyPI repository, aiming to compromise developers' endpoints and gain access to their customers' systems. While PyPI administrators ...
-
web:cybersecsentinel.com
Threat Group: Gleaming Pisces (also known as Citrine Sleet, Labyrinth Chollima, Nickel Academy, and UNC4736) Threat Type: Remote Access Trojan (RAT) Exploited Vulnerabilities: Supply chain attacks through Python Package Index (PyPI) Malware Used: PondRAT (variant of POOLRAT ) Threat Score: High (8.3/10) Last Threat Observation: September 22, 2024 Overview
-
web:lazarus.day
Based on our research into both RAT families, we assess that the new PondRAT is a lighter version of POOLRAT . The attackers behind this campaign uploaded several poisoned Python packages to PyPI, a popular repository of open-source Python packages.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the POOLRAT malware family including references, samples and yara signatures.
-
web:rewterz.com
Analysis Summary As part of an ongoing campaign, North Korean-affiliated threat actors have been seen deploying poisoned Python packages to spread a new piece of malware known as PondRAT. New research indicates that PondRAT is thought to be a more subdued form of POOLRAT , also known as SIMPLESEA. POOLRAT is a well-known macOS backdoor that was used in attacks linked to the 3CX supply chain ...
-
web:sos-vo.org
Palo Alto Networks' Unit 42 found that PondRAT is a lighter version of " POOLRAT ," also known as "SIMPLESEA," a macOS backdoor previously used by the "Lazarus Group" in attacks related to the 3CX supply chain compromise last year. This article continues to discuss findings regarding the new PondRAT malware .
-
web:thehackernews.com
North Korean hackers use poisoned Python packages from PyPI to spread PondRAT malware , targeting developers in a supply chain attack.
-
web:unit42.paloaltonetworks.com
Identical function names and encryption keys Similar execution flows We named this RAT family PondRAT. Further analysis revealed that PondRAT shared many characteristics with POOLRAT , another known macOS RAT in the arsenal of Gleaming Pisces. Based on these findings, we attribute the poisoned Python packages campaign to Gleaming Pisces.
-
web:www.cybersecurityintelligence.com
Malware Capabilities & Objectives PondRAT is described as a lighter version of POOLRAT , designed with enhanced capabilities for both Linux and macOS platforms. It includes functionality to upload and download files, execute arbitrary commands, and pause operations based on preconfigured time intervals.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.