#PondRAT
Malware/Tool
PondRAT is a remote-access backdoor used in Lazarus-linked financial and cryptocurrency operations and described as targeting macOS and Linux systems. Labyrinth Chollima delivered it through poisoned Python packages uploaded to the PyPI repository in a software-supply-chain campaign aimed at developers and potentially their downstream customers. Incident-response reporting observed PondRAT on disk alongside the memory-resident ThemeForestRAT before operators cleaned up those artifacts and transitioned to the more advanced RemotePE framework. Infrastructure research linked the family to fake meeting and scheduling sites and identified related domain and IP activity. Later analysis also noted that RemotePE's repeated file-overwrite deletion behavior had previously been associated with PondRAT and POOLRAT.
-
7
Tagged Reports
-
5
Unique Authors
-
628
Active Days