logo

Python Screenshotter Targets Tatar-Language Users

ID: 60dc3be7-6feb-5a98-9021-20cafaa06bb0

STIX ID: report--60dc3be7-6feb-5a98-9021-20cafaa06bb0

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2024-11-08

Date Updated: 2026-07-20

...
...

Cyble Research and Intelligence Labs observed a targeted malware campaign using a RAR-distributed PyInstaller executable masquerading as an image/video for Tatar Republic Day; the loader displays a benign image while executing PowerShell to download a ZIP from Dropbox, install a persistent PyInstaller binary (pyisgit.exe) via scheduled tasks, and run a PowerShell screenshotter (sc_new.ps1) that captures images in loops and exfiltrates them to a remote FTP server. The report includes full kill-chain details, file hashes, URLs/FTP server, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.