Hackers Use Phishing ZIP Files to Deploy PXA Stealer Against Financial Firms
ID: 4cbe9dee-d3f1-5d13-996f-0515850d9e05
STIX ID: report--4cbe9dee-d3f1-5d13-996f-0515850d9e05
Feed Name: cybersecurityNews.com
**PXA Stealer campaign targeting financial institutions:** CyberProof researchers observed a surge in PXA Stealer activity in Q1 2026 where phishing URLs deliver ZIP archives that unpack a Python-based infostealer (disguised using renamed binaries and legitimate Windows tools) to harvest browser credentials and crypto wallets and exfiltrate data via Telegram, with persistence achieved through registry modifications; the report maps the full kill chain, key artifacts (e.g., downloadtheproject.xyz, Pumaproject.zip, Document.docx.exe, Dots folder, svchost.exe), and recommended detection and mitigation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
