Python-Based PY#RATION Attack Campaign

February 8, 2023

The PY#RATION attack campaign used spear-phishing emails with malicious attachments to drop a remote access trojan. To avoid detection the attacker leveraged fernet encryption to hide the original source compounds and web sockets for command-and-control communication and exfiltration of data. The Python based malicious code is also compiled into a binary to infect the Windows operating system.