logo

SolyxImmortal - Analysis of a Python-based Information Stealer

ID: d9478647-38b2-5ca0-b15d-cd4b9ac3ee7d

STIX ID: report--d9478647-38b2-5ca0-b15d-cd4b9ac3ee7d

Feed Name: Pulsedive Blog

Threat Score
70/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Pulsedive Threat Research

...
...

SolyxImmortal is a Python-based information stealer that establishes persistence via a Run registry key, collects Chromium browser credentials, Firefox cookies, selected user documents (100 bytes–10 MB), periodic and keyword-triggered screenshots, and keystrokes, stages the data into a ZIP, and exfiltrates it (reported via Discord webhooks). The analysis documents execution flow, imported modules, collection and exfiltration routines, sample hashes/metadata, Turkish language indicators suggesting targeted victims, MITRE ATT&CK mappings, and recommended mitigations such as deploying EDR, restricting Python execution, and user education.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.