logo

Fileless Python Malware Uses Humanitarian Lures to Deploy Full-Spectrum Surveillance

ID: 127eb05d-ba4c-5323-a848-8b0525662fd6

STIX ID: report--127eb05d-ba4c-5323-a848-8b0525662fd6

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Ddos

...
...

Cyble Research reports a targeted cyberespionage campaign leveraging humanitarian-themed phishing (Russian-language lures) that delivers a fileless, heavily obfuscated Python implant via a malicious LNK in a RAR archive; the operators stage payloads from GitHub Releases, use PyArmor obfuscation, a Flask C2, and scheduled tasks for persistence to perform continuous surveillance, credential and file theft, keystroke logging, and live remote desktop access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.