OceanLotus-attributed ZiChatBot PyPI droppers: uuid32-utils, colorinal, termncolor with Zulip-API C2
Kaspersky GReAT (2026-05-08) re-attributed three PyPI wheels uploaded by an attacker between 2025-07-16 and 2025-07-22 - uuid32-utils, colorinal, and termncolor - to the Vietnam-aligned OceanLotus (APT32) group. The droppers fetch a Windows DLL or Linux .so, persist via Run-key or crontab, and load ZiChatBot, a Python backdoor that uses public Zulip REST APIs as its C2 channel to blend with normal developer traffic.
Versions named here: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4