logo

Python Infostealer Hides in GitHub Releases to Bypass Detection

ID: 055bcdc2-b9e6-5f94-af16-3fe6f7b276c7

STIX ID: report--055bcdc2-b9e6-5f94-af16-3fe6f7b276c7

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Mayura Kathir

...
...

**Operation HumanitarianBait**: A targeted Python-based infostealer campaign leverages humanitarian-themed LNK phishing lures and GitHub Releases to bootstrap a PE-less Python runtime under %APPDATA%\\WindowsHelper, deploy PyArmor-protected payloads, maintain persistence via VBScript and a Scheduled Task named WindowsHelper, steal browser credentials and Telegram session data, log keystrokes, capture screenshots, and exfiltrate data to an nginx/Flask C2; the report includes SHA-256 hashes, malicious URLs, and guidance to monitor for related artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.