logo

Bidirectional communication via polyrhythms and shuffles: Without Jon the beat must go on

ID: a75bc741-edae-558a-b112-14ee3d925350

STIX ID: report--a75bc741-edae-558a-b112-14ee3d925350

Feed Name: Cisco Talos

Threat Score
70/100

Date Published: 2024-11-21

Date Updated: 2026-04-27

Author: William Largent

...
...

Cisco Talos reports an active information-stealing campaign (PXA Stealer) attributed to a Vietnamese-speaking threat actor targeting government and education organizations in Europe and Asia; the malware harvests credentials, VPN/FTP data, browser cookies and can decrypt browser master passwords to exfiltrate stored credentials. Talos published Snort rules and ClamAV signatures to detect and defend against PXA Stealer; the newsletter also highlights related telemetry (malware hashes) and other security headlines including malicious NPM packages and a Palo Alto Networks firewall vulnerability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.