Banana Squad is a malware distribution cluster tracked for abusing open-source software ecosystems, particularly GitHub and previously the Python Package Index, to spread trojanized Python-based tools. The activity has been assessed as a continuation of a 2023 rogue PyPI campaign in which bogus Python packages were widely downloaded and delivered information-stealing functionality against Windows systems. The actor’s tradecraft centers on software supply chain abuse and social engineering of users seeking offensive security utilities, account checkers, cheats, and similar tools. Repositories masquerade as benign or desirable projects while embedding malicious payloads or downloader logic. Reported lures included tools themed around social media, gaming, and payment-account abuse. The operation relied on numerous lookalike repositories impersonating legitimate projects in order to increase trust and drive victim downloads. Observed capabilities include initial access through trojanized software, credential and data theft, session theft, cryptocurrency wallet targeting, persistence through follow-on payloads, and broader post-exploitation via remote-access malware. Related payload behavior included harvesting sensitive information, downloading additional Python components, and injecting malicious code into a cryptocurrency wallet application. The campaign fits a broader pattern of GitHub abuse for malware delivery, but Banana Squad specifically refers to the cluster tied to the rogue Python ecosystem and the trojanized GitHub repositories linked to it. Banana Squad appears financially motivated, with targeting and payload design aligned to theft of credentials, browser data, session material, and cryptocurrency-related assets rather than espionage or destructive objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Software supply-chain style activity using trojanized files hosted in numerous GitHub repositories to distribute malicious code.
Conducting a software supply chain campaign using trojanized GitHub repositories and previously bogus PyPI packages that masquerade as Python-based hacking tools in order to deliver information-stealing payloads and additional malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.