MALICIOUS (1) campaign cataloged at 2026-09-27(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2026-09-caracas4check¶
During installation, the code downloads a malicious executable from a remote location. The malicious action is triggered only on specific hosts.
Abuse categories¶
obfuscation
Code uses obfuscation techniques to hide its true purpose.
override_install
The package overrides the install command in setup.py to execute malicious code during installation.
remote_executable
Downloads and executes a remote executable.
targetted-attack
Campaign uses targetted-attack.
References¶
Referenced resources may include blog posts about the campaign, malware analysis, sandbox reports, or other relevant information.
IoCs & related URLs¶
URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.
-
185.241.208.139 -
hxxps://185.241.208.139/fbe1286357a09e81b12243baad454c0b544c6cf3c4d6245e56e13581b4b33709/x