#WebLogTea
Malware/Tool
2024-02-29 • Novel ELF64 Remote Access Tool Embedded in Malicious PyPI Uploads
WebLogTea does not denote a coherent malware family in the associated publications. One is a broad overview of advanced persistent threat activity, while the other analyzes an unnamed Linux x86-64 remote-access tool delivered through typosquatted PyPI packages. That ELF payload uses libcurl and HTTPS to beacon, upload and download files, run commands with or without returning output, and vary its polling interval.
-
2
Tagged Reports
-
2
Unique Authors
-
77
Active Days