Python Infostealer Hides in GitHub Releases to Bypass Detection
ID: 055bcdc2-b9e6-5f94-af16-3fe6f7b276c7
STIX ID: report--055bcdc2-b9e6-5f94-af16-3fe6f7b276c7
Feed Name: GBHackers
**Operation HumanitarianBait**: A targeted Python-based infostealer campaign leverages humanitarian-themed LNK phishing lures and GitHub Releases to bootstrap a PE-less Python runtime under %APPDATA%\\WindowsHelper, deploy PyArmor-protected payloads, maintain persistence via VBScript and a Scheduled Task named WindowsHelper, steal browser credentials and Telegram session data, log keystrokes, capture screenshots, and exfiltrate data to an nginx/Flask C2; the report includes SHA-256 hashes, malicious URLs, and guidance to monitor for related artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
