#RNLoader

Malware/Tool

2025-04-14 • Slow Pisces Targets Developers With Coding Challenges and Introduces New Customized Python Malware

RN Loader is a Python malware loader used by Slow Pisces against cryptocurrency developers through fake LinkedIn recruitment and compromised coding-challenge repositories. A malicious server selectively returned YAML that exploited unsafe PyYAML deserialization, wrote RN Loader to ~/Public/init.py, and executed it. The loader deletes its file, reports basic host and operating-system information over HTTPS, and enters a command loop. It can decode and load a DLL, execute Base64-encoded Python, launch a downloaded native payload, sleep, or terminate, and it delivered the macOS-focused RN Stealer in memory.

Tagged Reports

« Back