s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-py.pxa_stealer

📛 Threat Title

Malware family: PXA Stealer

Category: PXA Stealer First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `py.pxa_stealer`. Printable name: PXA Stealer. Aliases: PXAStealer,PXA.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:assets.kpmg.com

    PXA Stealer is a Python-based information-stealing malware first identified in late 2024, attributed to a Vietnamese-speaking threat actor. It has evolved with advanced anti-analysis techniques and a robust command-and-control infrastructure. The malware primarily targets government and education sectors and is believed to have compromised thousands of unique IPs across 62 countries, with ...

  • web:blog.talosintelligence.com

    We discovered a new Python program called PXA Stealer that targets victims' sensitive information, including credentials for various online accounts, VPN and FTP clients, financial information, browser cookies, and data from gaming software.

  • web:cybersecsentinel.com

    Threat Group: Vietnamese-speaking cybercrime actors (possible overlap with CoralRaider) Threat Type: Python-based Information Stealer (Infostealer) Exploited Vulnerabilities: DLL sideloading, phishing ZIP archives, abuse of legitimate cloud services (Cloudflare Workers, Dropbox) Malware Used: PXA Stealer Threat Score: 🔥 Critical (9.0/10) - Due to advanced evasion, large-scale credential ...

  • web:cybersecuritynews.com

    A new wave of cyberattacks is putting financial institutions on high alert, as threat actors ramp up the use of PXA Stealer — a powerful information-stealing malware — against organizations worldwide. The surge follows law enforcement's successful dismantling of major infostealer operations, including Lumma, Rhadamanthys, and RedLine, throughout 2025. With those platforms gone, PXA ...

  • web:malpedia.caad.fkie.fraunhofer.de

    PXA Stealer is an information-stealing malware written in Python, identified by Cisco Talos in an active campaign attributed to a Vietnamese-speaking threat actor (2024). The stealer targets sensitive data such as credentials for online accounts, VPN and FTP clients, financial information, browser cookies, and gaming-related data.

  • web:thehackernews.com

    PXA Stealer infects 4,000+ IPs, stealing 200K passwords via Telegram, affecting users and firms globally.

  • web:undercodetesting.com

    The analysis reveals that PXA Stealer employs classic yet refined techniques—phishing, archive attachments, and credential theft. Its success lies in exploiting the trust users place in ZIP files and the lag in detection for novel malware .

  • web:www.cyberproof.com

    This in-depth analysis of the PXA Stealer attack methodology provides a critical look into the evolving tactics of cybercriminals. By detailing the malware's sophisticated techniques - from its initial delivery via malicious RAR attachments to its use of DLL sideloading, injection , LOLBin abuse and data exfiltration - we hope to equip ...

  • web:www.infosecurity-magazine.com

    A newly identified Python-based malware known as PXA Stealer has been observed as part of a widespread cybercriminal campaign that has stolen sensitive data from victims in more than 60 countries. The operation, called "Ghost in the Zip" by security researchers, has been tracked by SentinelLabs ...

  • web:www.sentinelone.com

    PXA Stealer uses advanced evasion and Telegram C2 to steal global victim data, fueling a thriving cybercrime market.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.