logo

Obfuscated Malicious Python Scripts with PyArmor, (Wed, Apr 9th)

ID: b8f2e86f-9bb1-5db2-b4e9-eadb42371758

STIX ID: report--b8f2e86f-9bb1-5db2-b4e9-eadb42371758

Feed Name: SANS ISC Diary

Threat Score
75/100

Date Published: 2025-04-09

Date Updated: 2026-04-19

...
...

This report examines PyArmor-obfuscated malicious Python scripts delivered by a PowerShell one-liner that downloads a bundled Python runtime (python3.zip) containing an obfuscated exec.py; the analyst uses Frida to hook PyMarshal_ReadObjectFromString and memory-dump the process to recover strings and confirm stealer behavior (browser/process targeting, credit card and wallet artifact searches), and provides associated IOAs/IOCs and analysis techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.