logo

NodeStealer Spyware Adds Keylogging, Screenshot Capture and Facebook Data Theft

ID: 3dc27a00-90ce-574d-baac-3576031a8845

STIX ID: report--3dc27a00-90ce-574d-baac-3576031a8845

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-09-04

Date Updated: 2026-09-11

Author: Mayura Kathir

...
...

A newly observed August 2026 variant of NodeStealer has expanded from a Facebook-focused infostealer into a full-featured Python spyware platform that logs keystrokes, monitors the clipboard, captures screenshots, and harvests extensive Facebook profile, Pages, and Ads Manager data across multiple browsers; it uses split Telegram bots for exfiltration and includes .pyc artifacts that complicate analysis. Netskope researchers observed targeting of organizations in Asia and North America (notably financial services) and recommend monitoring for suspicious Python execution, Telegram Bot API traffic, access to browser SQLite databases, clipboard/screenshot libraries, and anomalous .pyc metadata while strengthening Facebook Business/Ads security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.