logo

New PXA Stealer Malware Targets Banks, Uses Telegram to Exfiltrate Data

ID: 28891839-ceae-5b3c-9282-ba37791b0ff3

STIX ID: report--28891839-ceae-5b3c-9282-ba37791b0ff3

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-03-26

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

CyberProof reports an 8–10% rise in PXA Stealer campaigns in Q1 2026 targeting financial firms; the malware is distributed via convincing phishing emails and malicious ZIPs (e.g., Pumaproject.zip), establishes persistence via registry entries, renames itself (svchost.exe), stores components in a hidden Dots folder (password: shodan2201), harvests browser credentials and crypto keys, and exfiltrates stolen data to Telegram channels (using BOT_ID Verymuchxbot); recommended defenses include skepticism toward unsolicited archives, monitoring suspicious domains (.xyz/.shop), and blocking unexpected .vbs/.js files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.