logo

Fraud Investigation Reveals Sophisticated Python Malware

ID: ebe303c4-8733-5cc7-b920-4f3118d52fec

STIX ID: report--ebe303c4-8733-5cc7-b920-4f3118d52fec

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-02-23

Date Updated: 2026-04-22

...
...

Secuinfra uncovered a sophisticated Python-based malware deployment discovered after a fraud investigation: attackers used hidden PowerShell downloads (svchoss.exe) from an IP hosted in Tencent networks, deployed an obfuscated PyInstaller payload and a concealed Python environment, and operated Cobalt Strike beacons and persistence via startup scripts; extracted artifacts indicate credential- and wallet-theft and active unauthorized PayPal transfers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.