logo

Phishing ZIP Files Used to Deploy PXA Stealer Targeting Financial Firms

ID: 05080f4b-4988-5d4d-a025-540121f393db

STIX ID: report--05080f4b-4988-5d4d-a025-540121f393db

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-03-27

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

### Executive summary Researchers observed a notable surge in PXA Stealer campaigns in Q1 2026 targeting global financial institutions: attackers deliver ZIP/RAR phishing lures containing executables (e.g., Document.docx.exe) that unpack a Python interpreter renamed as svchost.exe, use LOLBins (certutil, renamed WinRAR) to decode and extract payloads, harvest browser credentials and crypto wallets, and exfiltrate stolen data via Telegram while maintaining persistence through registry changes. Mitigations recommended include monitoring for suspicious archives and script execution from email/temp directories, hunting for renamed binaries in non-standard locations, and tracking outbound connections to unusual domains and messaging platforms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.