OceanLotus suspected of using PyPI to deliver ZiChatBot malware

2026-05-06T20:51:56Zf6b03e41e502083b7483e8dc35f98e6b07d253cc3c3c3c9ca8acd0b02d52e394
ABCDoorAmazon SESApp StoreBECClipBankerFakeWalletLinuxOceanLotusPhantomRPCPyPIRPC vulnerabilitySilver FoxValleyRATWindowsZiChatBotfinancial-malwareiOSindustrial-threatsmalwarephishingprivilege-escalationpython-wheelrepository-poisoningsoftware-supply-chaintrojanized-software

What happened

Kaspersky Securelist feed (May 2026) describes multiple active campaigns and new technical findings: malicious Python wheel packages on PyPI delivering a dropper that installs ZiChatBot (Windows and Linux) — attributed to OceanLotus APT — indicating a supply‑chain / repository poisoning vector; Silver Fox campaigns impersonating tax authorities distributing ValleyRAT and a new ABCDoor backdoor against targets in Russia and India; discovery of a PhantomRPC vulnerability enabling fake RPC servers and local privilege escalation on Windows; a cluster of FakeWallet iOS phishing apps in the AppStore

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
f6b03e41e502083b7483e8dc35f98e6b07d253cc3c3c3c9ca8acd0b02d52e394
Enrichment time
2026-05-06T20:51:56Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · OceanLotus suspected of using PyPI to deliver ZiChatBot malware · Baitaphish