logo

Ghost in the Zip | New PXA Stealer and Its Telegram-Powered Ecosystem

Threat Score
80/100

Date Published: 2025-08-04

Date Updated: 2026-07-27

Author: Jim Walter, Alex Delamotte, Beazley Security’s Francisco Donoso, Sam Mayers, Tell Hause & Bobby Venal

...
...

SentinelLABS and Beazley Security uncovered an active, evolving infostealer campaign centered on the Python-based PXA Stealer that uses signed legitimate binaries (e.g., Haihaisoft PDF Reader, Word 2013) and DLL sideloading to deploy obfuscated Python payloads, evade sandboxes, and persist via Registry Run keys; the stealer harvests passwords, cookies, crypto wallet data and other sensitive artifacts from thousands of victims across 62+ countries and exfiltrates data to Telegram channels via Cloudflare Workers, with extensive IoCs provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.