logo

SolyxImmortal Malware Abuses Discord to Quietly Harvest Sensitive Information

ID: b48ed614-0ef7-542f-9fad-36f0f536eac2

STIX ID: report--b48ed614-0ef7-542f-9fad-36f0f536eac2

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-20

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

SolyxImmortal is a newly observed Python-based Windows info-stealer (detected Jan 2026) that persistently collects browser-stored credentials, documents, keystrokes, and screenshots, stages and compresses data, and exfiltrates via hardcoded Discord webhooks; it achieves user-space persistence by copying itself to AppData and registering in the user's Run registry and is reported to be distributed through underground Telegram channels, with a provided SHA-256 IOC.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.