logo

NodeStealer Can Now Record Everything Victims Type and Steal Their Screenshots

ID: fa8c5a8e-084a-5492-8571-e13cab315055

STIX ID: report--fa8c5a8e-084a-5492-8571-e13cab315055

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-09-04

Date Updated: 2026-09-16

Author: Tushar Subhra Dutta

...
...

NodeStealer, previously focused on stealing browser credentials and Facebook accounts, has evolved into a more invasive Python-based infostealer that now includes a persistent keylogger (using pynput), clipboard monitoring, and screen capture; stolen data is exfiltrated via Telegram bots. Netskope observed the upgraded samples in August 2026 affecting mainly Asia and North America with financial services targeted; the malware queries expanded Facebook Graph API endpoints to harvest business and Ads Manager data, uses altered Python bytecode to hinder analysis, and includes IoCs such as a temporary keystroke log filename pattern.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.