logo

New PXA Stealer targets government and education sectors for sensitive information

ID: 4b8219e8-c5d2-5f03-b66b-1a31cce86e68

STIX ID: report--4b8219e8-c5d2-5f03-b66b-1a31cce86e68

Feed Name: Cisco Talos

Threat Score
75/100

Date Published: 2024-11-14

Date Updated: 2026-04-27

Author: Joey Chen

...
...

Cisco Talos describes an active campaign using a Python-based information stealer called PXA Stealer, distributed via a Rust loader inside malicious ZIP attachments. The malware decrypts browser master keys (Chrome/Chromium and Firefox), extracts credentials, cookies, credit card and wallet data, Discord tokens, and other application data, then compresses and exfiltrates victims' data to attacker-controlled Telegram bots; Talos also documents attacker infrastructure (tvdseo.com), Telegram accounts/channels used for selling tools and credentials, detailed infection and persistence mechanisms, and provides IOCs for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.