NodeStealer Spyware Adds Keylogging, Screenshot Capture and Facebook Data Theft
ID: 3dc27a00-90ce-574d-baac-3576031a8845
STIX ID: report--3dc27a00-90ce-574d-baac-3576031a8845
Feed Name: GBHackers
A newly observed August 2026 variant of NodeStealer has expanded from a Facebook-focused infostealer into a full-featured Python spyware platform that logs keystrokes, monitors the clipboard, captures screenshots, and harvests extensive Facebook profile, Pages, and Ads Manager data across multiple browsers; it uses split Telegram bots for exfiltration and includes .pyc artifacts that complicate analysis. Netskope researchers observed targeting of organizations in Asia and North America (notably financial services) and recommend monitoring for suspicious Python execution, Telegram Bot API traffic, access to browser SQLite databases, clipboard/screenshot libraries, and anomalous .pyc metadata while strengthening Facebook Business/Ads security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
