logo

The Python Predator: PXA Stealer Surges 10% as it Targets Global Finance and Crypto in 2026

ID: e57f4729-9de2-507a-b868-315092375a3e

STIX ID: report--e57f4729-9de2-507a-b868-315092375a3e

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-06

Date Updated: 2026-04-23

Author: Ddos

...
...

PXA Stealer has surged in Q1 2026 targeting financial institutions and crypto users via phishing emails that deliver compromised ZIP attachments (e.g., Pumaproject.zip). The malware executes a multi-stage chain using living-off-the-land tools (certutil), hides components in directories like “Dots”, extracts a portable Python interpreter renamed to svchost.exe, injects into browsers to steal credentials and wallets, monitors keystrokes via WINWORD.EXE hooks, and exfiltrates collected data through Telegram channels.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.