logo

Hackers Use Phishing ZIP Files to Deploy PXA Stealer Against Financial Firms

ID: 4cbe9dee-d3f1-5d13-996f-0515850d9e05

STIX ID: report--4cbe9dee-d3f1-5d13-996f-0515850d9e05

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-27

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**PXA Stealer campaign targeting financial institutions:** CyberProof researchers observed a surge in PXA Stealer activity in Q1 2026 where phishing URLs deliver ZIP archives that unpack a Python-based infostealer (disguised using renamed binaries and legitimate Windows tools) to harvest browser credentials and crypto wallets and exfiltrate data via Telegram, with persistence achieved through registry modifications; the report maps the full kill chain, key artifacts (e.g., downloadtheproject.xyz, Pumaproject.zip, Document.docx.exe, Dots folder, svchost.exe), and recommended detection and mitigation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.