NodeStealer Can Now Record Everything Victims Type and Steal Their Screenshots
ID: fa8c5a8e-084a-5492-8571-e13cab315055
STIX ID: report--fa8c5a8e-084a-5492-8571-e13cab315055
Feed Name: cybersecurityNews.com
NodeStealer, previously focused on stealing browser credentials and Facebook accounts, has evolved into a more invasive Python-based infostealer that now includes a persistent keylogger (using pynput), clipboard monitoring, and screen capture; stolen data is exfiltrated via Telegram bots. Netskope observed the upgraded samples in August 2026 affecting mainly Asia and North America with financial services targeted; the malware queries expanded Facebook Graph API endpoints to harvest business and Ads Manager data, uses altered Python bytecode to hinder analysis, and includes IoCs such as a temporary keystroke log filename pattern.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
