#RNLoader
Malware/Tool
2025-04-14 • Slow Pisces Targets Developers With Coding Challenges and Introduces New Customized Python Malware
RN Loader is a Python malware loader used by Slow Pisces against cryptocurrency developers through fake LinkedIn recruitment and compromised coding-challenge repositories. A malicious server selectively returned YAML that exploited unsafe PyYAML deserialization, wrote RN Loader to ~/Public/init.py, and executed it. The loader deletes its file, reports basic host and operating-system information over HTTPS, and enters a command loop. It can decode and load a DLL, execute Base64-encoded Python, launch a downloaded native payload, sleep, or terminate, and it delivered the macOS-focused RN Stealer in memory.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days