logo

Python Infostealer Uses GitHub Releases To Bypass Security Tools

ID: deba664c-8463-59bd-9368-f49527c63cc7

STIX ID: report--deba664c-8463-59bd-9368-f49527c63cc7

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Varshini

...
...

Operation HumanitarianBait is an active cyberespionage campaign that delivers a stealthy, Python-based infostealer via phishing emails containing a malicious LNK file inside a RAR archive. The attack executes PowerShell to run obfuscated payloads in memory, fetches the primary implant from GitHub Releases (to blend with legitimate traffic), uses PyArmor obfuscation, and exfiltrates browser credentials, Telegram sessions, keystrokes, clipboard data and screenshots while establishing persistence and remote access via scheduled tasks and legitimate remote‑access tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.