Phishing ZIP Files Used to Deploy PXA Stealer Targeting Financial Firms
ID: 05080f4b-4988-5d4d-a025-540121f393db
STIX ID: report--05080f4b-4988-5d4d-a025-540121f393db
Feed Name: GBHackers
### Executive summary Researchers observed a notable surge in PXA Stealer campaigns in Q1 2026 targeting global financial institutions: attackers deliver ZIP/RAR phishing lures containing executables (e.g., Document.docx.exe) that unpack a Python interpreter renamed as svchost.exe, use LOLBins (certutil, renamed WinRAR) to decode and extract payloads, harvest browser credentials and crypto wallets, and exfiltrate stolen data via Telegram while maintaining persistence through registry changes. Mitigations recommended include monitoring for suspicious archives and script execution from email/temp directories, hunting for renamed binaries in non-standard locations, and tracking outbound connections to unusual domains and messaging platforms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
