Security News > 2023 > August > North Korean hackers behind malicious VMConnect PyPI campaign

North Korean hackers behind malicious VMConnect PyPI campaign
2023-08-31 18:47

North Korean state-sponsored hackers are behind the VMConnect campaign that uploaded to the PyPI repository malicious packages, one of them mimicking the VMware vSphere connector module vConnector.

A report today from ReversingLabs, a software supply chain security company, attributes the campaign to Labyrinth Chollima, a subgroup of North Korean Lazarus hackers.

The researchers discovered more packages that are part of the same VMConnect operation, namely 'tablediter', 'request-plus', and 'requestspro'.

Although they did not analyze the final payload, ReversingLabs researchers say that they collected enough evidence to link the VMConnect campaign to the infamous North Korean Lazarus APT group.

Py' file in the malicious packages, which contains the same payload decoding routine that JPCERT, Japan's Computer Security Incident Response Team found on another file called 'py Qrcode.

North Korean hackers 'ScarCruft' breached Russian missile maker.


News URL

https://www.bleepingcomputer.com/news/security/north-korean-hackers-behind-malicious-vmconnect-pypi-campaign/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Pypi 14 0 0 14 0 14