Back to Intel

Intel Node

OceanLotus suspected of using PyPI to deliver ZiChatBot malware

lowmalware2026-05-06T13:00:34+00:00source excerpt
malwarewindowslinuxemail

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Kaspersky researchers uncovered malicious wheel packages in PyPI that targeted both Windows and Linux and contained a dropper delivering malware dubbed ZiChatBot. We attribute this activity to OceanLotus APT.

Introduction Through our daily threat hunting, we noticed that, beginning in July 2025, a series of malicious wheel packages were uploaded to PyPI (the Python Package Index). We shared this information with the public security community, and the malware was removed from the repository. We submitted the samples to Kaspersky Threat Attribution Engine (KTAE) for analysis. Based on the results, we believe the packages may be linked to malware discussed in a Threat Intelligence report on OceanLotus. While these wheel packages do implement the features described on their PyPI web pages, their true purpose is to covertly deliver malicious files.

These files can be either . DLL or . SO (Linux shared library), indicating the packages’ ability to target both Windows and Linux platforms.

Read Original Source