logo

SolyxImmortal Info Stealer Exploits Systems via Discord

ID: c54bbed1-0a42-59a2-bdbc-c8c2391ac529

STIX ID: report--c54bbed1-0a42-59a2-bdbc-c8c2391ac529

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-31

Date Updated: 2026-05-31

Author: Ddos

...
...

This report details the SolyxImmortal Python-based info stealer that achieves persistence on Windows (copying itself to APPDATA and adding a Run key), harvests browser-stored credentials and cookies (including Chromium-based and Firefox databases), searches and exfiltrates local documents within a defined size range, records keystrokes and periodic/screenshots (including keyword-triggered captures for banking/crypto/Gmail), and sends stolen data via Discord webhooks; Turkish language artifacts in the configuration suggest targeting of Turkish-speaking users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.