Hackers linked to North Korea are using malicious Python packages as a way to deliver a new malware called PondRAT as part of an ongoing campaign.
See also: Clipper malware attacks threaten crypto—what you can do

The PondRAT malware, according to new findings from Palo Alto Networks Unit 42, is believed to be a lighter version of POOLRAT (also known as SIMPLESEA), a known macOS backdoor previously attributed to the Lazarus and deployed in attacks related to the 3CX supply chainlast year.
Some of these attacks are part of a persistent cyberattack campaign called Operation Dream Job, where prospective targets are lured with job offers in an attempt to trick them into downloading malware.
The hackers are also being monitored by the wider cybersecurity community under the names Citrine Sleet, Labyrinth Chollima, Nickel Academy , and UNC4736 , as a subgroup within the Lazarus Group that is also known for distributing the AppleJeus malware .
It is believed that the ultimate goal of the attacks is “endpoints developers’ then gain access to the suppliers’ customer endpoints, as observed in previous incidents.”
See also: SambaSpy Malware: Targets Italian users with phishing emails
The list of malicious packages, which have now been removed from the PyPI repository, includes:
- real-ids (893 downloads)
- coloredtxt (381 downloads)
- beautifultext (736 downloads)
- minisound (416 downloads)
The infection chain is quite simple as the packages, once downloaded and installed on developers' systems, are designed to execute a coded next stage which, in turn, executes the Linux and macOS versions of the PondRAT malware after being retrieved from a remote server.

Further analysis of PondRAT revealed similarities to both POOLRAT and AppleJeus, with the attacks also distributing new Linux of POOLRAT.
The PondRAT malware, a more streamlined version of POOLRAT, has the ability to send and receive files, pause operations for a predetermined period of time, and execute arbitrary commands.
The revelation comes as KnowBe4, which was tricked into hiring a North Korean hacker as an employee, said more than a dozen companies “either hired North Korean employees or were besieged by a flood of fake resumes and applications submitted by North Koreans hoping to land a job at their organization.”
He described the activity, which CrowdStrike under the name Famous Chollima, as “a serious risk for any company with remote-only employees.”
See also: TeamTNT Malware: Targets CentOS Servers Using Rootkit
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
A Remote Access Trojan (RAT), such as the PondRAT malware, is a type of malware used by attackers to gain unauthorized access and control over a computer or network. Once installed on a target system, a RAT can operate invisibly, allowing the attacker to monitor user behavior, access confidential information, activate webcams, and manipulate files or applications. RATs are often distributed via phishing emails, malicious downloads, or software vulnerabilities. Due to their stealthy nature, they pose a significant threat to both individual users and organizations, highlighting the importance of strong cybersecurity measures to detect and prevent such intrusions.
Source: thehackernews
