The Python Predator: PXA Stealer Surges 10% as it Targets Global Finance and Crypto in 2026
ID: e57f4729-9de2-507a-b868-315092375a3e
STIX ID: report--e57f4729-9de2-507a-b868-315092375a3e
Feed Name: securityonline.info
PXA Stealer has surged in Q1 2026 targeting financial institutions and crypto users via phishing emails that deliver compromised ZIP attachments (e.g., Pumaproject.zip). The malware executes a multi-stage chain using living-off-the-land tools (certutil), hides components in directories like “Dots”, extracts a portable Python interpreter renamed to svchost.exe, injects into browsers to steal credentials and wallets, monitors keystrokes via WINWORD.EXE hooks, and exfiltrates collected data through Telegram channels.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
