Python Screenshotter Targets Tatar-Language Users
ID: 60dc3be7-6feb-5a98-9021-20cafaa06bb0
STIX ID: report--60dc3be7-6feb-5a98-9021-20cafaa06bb0
Feed Name: Cyble Blog
Cyble Research and Intelligence Labs observed a targeted malware campaign using a RAR-distributed PyInstaller executable masquerading as an image/video for Tatar Republic Day; the loader displays a benign image while executing PowerShell to download a ZIP from Dropbox, install a persistent PyInstaller binary (pyisgit.exe) via scheduled tasks, and run a PowerShell screenshotter (sc_new.ps1) that captures images in loops and exfiltrates them to a remote FTP server. The report includes full kill-chain details, file hashes, URLs/FTP server, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
