Pisces

Language updated a month ago (2024-09-24T08:21:21.352Z)
Download STIX
Preview STIX
Pisces is a sophisticated malware attributed to the North Korean Advanced Persistent Threat (APT) group, Gleaming Pisces. This malicious software has been linked to multiple cyber-espionage campaigns and is known for its capability to exploit and damage computer systems across various platforms. Pisces can infect systems through suspicious downloads, emails, or websites, often without the user's knowledge. Once inside, it can steal personal information, disrupt operations, or even hold data hostage for ransom. The malware has evolved over time, with evidence of additional Linux variants of a related malware, POOLRAT, indicating that Gleaming Pisces has been enhancing its capabilities across both Linux and macOS platforms. The connection between Pisces and other malware such as PondRAT and POOLRAT has been established through extensive research and analysis. Investigations have revealed that PondRAT shares code similarities with POOLRAT, another malware previously attributed to Gleaming Pisces. Moreover, an examination of the Linux variant of PondRAT, dropped as the final payload in one of the campaigns, showed significant similarities to other malware attributed to Gleaming Pisces, including kupayupdate_stage2. These findings further strengthen the attribution of these campaigns to Gleaming Pisces. The 27th Colloquium featured the 2023 Conference on Cybersecurity Education, Research and Practice (CCERP), where the 5th Annual PISCES academic workshop was held. During this event, discussions included comparisons of PondRAT to previous Gleaming Pisces attributed malware and the poisoned Python packages campaign tied to the Gleaming Pisces APT group. Additionally, ESET identified similarities between POOLRAT and a backdoor called BADCALL for Linux, also attributed to Gleaming Pisces. This ongoing research and analysis continue to shed light on the evolving threat landscape posed by the Gleaming Pisces APT group and their associated malware.
Description last updated: 2024-09-19T02:16:25.553Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.