Python Infostealer Uses GitHub Releases To Bypass Security Tools
ID: deba664c-8463-59bd-9368-f49527c63cc7
STIX ID: report--deba664c-8463-59bd-9368-f49527c63cc7
Feed Name: Cyber Press
Operation HumanitarianBait is an active cyberespionage campaign that delivers a stealthy, Python-based infostealer via phishing emails containing a malicious LNK file inside a RAR archive. The attack executes PowerShell to run obfuscated payloads in memory, fetches the primary implant from GitHub Releases (to blend with legitimate traffic), uses PyArmor obfuscation, and exfiltrates browser credentials, Telegram sessions, keystrokes, clipboard data and screenshots while establishing persistence and remote access via scheduled tasks and legitimate remote‑access tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
