botaa3 Malware Resides in Fake PyPi Python Packages

Lately, more and more cybercriminals have been planting their malicious software inside repositories for scripts, browser add-ons, or other sort of content. One of the recent examples of this is the botaa3 Malware, which appears to reside in a malicious PyPi package. PyPi, or the Python Package Index, is a repository for millions of Python code snippets and scripts that developers share with each other. Of course, the botaa3 Malware is not a legitimate script – it executes malicious tasks if it is executed on an unprotected system.

The creators of the botaa3 Malware are mimicking the name of one of the more popular PyPi packages – boto3. The botaa3 Malware comes in a heavily-obfuscated PyPi package, which relies on XOR encryption. But what does the payload hide?

The Contents of the botaa3 Malware

Once the script is launched, it will connect to the attacker's server that also uses a misleading domain name – install.pypi-installer.com. The control server receives some information from the implant:

  • The IP & Mac address of the victim.
  • The version of the operating system.
  • Username & hostname.
  • The process ID of the payload.

The attacker is able to control the botaa3 Malware via remotely sent commands. The malware is able to upload and download files, manage the file system, execute remote commands, and load additional Python scripts. This means that the botaa3 Malware can be very flexible in terms of functionality, further enhancing its attack potential.

Protecting your system from the botaa3 Malware and similar payloads requires the use of antivirus software that is up-to-date. Also, make sure to always download content from trustworthy sources – as you can see, criminals often mimic the names of legitimate sites, services, and files.

November 30, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.