PXA Stealer is a Python-based Windows information stealer first publicly documented in 2024 and associated with Vietnamese-speaking cybercriminal actors. It targets browser-stored credentials, saved passwords, session cookies, autofill data, authentication tokens, financial information, cryptocurrency-wallet data, and sensitive data from applications including VPN clients, cloud command-line utilities, messaging clients, password managers, and connected file shares. It enumerates Chromium- and Gecko-based browser profiles, decrypts stored browser data, and has used browser-process injection to target browser encryption protections.
PXA Stealer is commonly distributed through phishing and recruitment-themed lures, including malicious compressed archives and disguised document executables. Observed delivery chains abuse legitimate signed applications for DLL side-loading, decoy documents, renamed Python runtimes, encrypted embedded archives, and Windows utilities to decode or unpack later-stage components. The malware uses obfuscation, masquerading, in-memory execution, and abuse of trusted services to hinder analysis and detection.
Collected data is packaged into archives and exfiltrated through Telegram-controlled infrastructure, including intermediary web-service relays. Observed variants establish persistence through Registry Run keys or scheduled tasks. Campaigns have targeted job seekers, government and education organizations, global financial institutions, and victims across dozens of countries. Stolen data has been linked to a Telegram-based criminal ecosystem used for downstream account abuse and resale.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PXA Stealer est un infostealer basé sur Python capable de : Extraire les cookies de session, mots de passe enregistrés et données de remplissage automatique des navigateurs... Router automatiquement les données volées vers des bots Telegram contrôlés par le groupe... Intégrer des outils d’accès à distance permettant le contrôle des machines infectées via des serveurs privés virtuels (VPS).
PXA Stealer est un infostealer basé sur Python capable de : Extraire les cookies de session, mots de passe enregistrés et données de remplissage automatique des navigateurs... Router automatiquement les données volées vers des bots Telegram contrôlés par le groupe... Intégrer des outils d’accès à distance permettant le contrôle des machines infectées via des serveurs privés virtuels (VPS).
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
During a wave of attacks occurring in April 2025, users were phished or otherwise lured into downloading a compressed archive... The large archive attached to the phishing lure contained...
Fichiers exécutables déguisés en PDFs ou documents ordinaires, distribués par campagnes d’e-mails massifs
Threat actors have moved away from purpose-built malicious infrastructure and toward legitimate, high-reputation sending platforms that email security tools are configured to trust. Mimecast’s telemetry shows that among these campaigns, about one in three detections arrived through Salesforce infrastructure, with another quarter delivered through Google Workspace mail-merge tools and SharePoint-hosted links.
Upon execution, the malicious DLL creates a .CMD script Evidence.cmd in the current directory, which orchestrates all subsequent steps in the attack chain... The sideloaded DLL then launches a hidden instance of Command Prompt and begins a multi-stage chain of activity.
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
The infostealer will also attempt to inject a DLL into running instances of browsers such as Chrome, targeting Chrome’s App-Bound Encryption Key to defeat the internal encryption schemes within Chrome.
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
These campaigns use elaborate staging layers that obscure their purpose and delay detection... launches a heavily obfuscated Python script... Once downloaded, the obfuscated Python code is decoded and executed
embedded archives disguised as common file types... a legitimate WinRar executable also hosted in the “-“ folder renamed images.png... The Python interpreter is renamed to svchost.exe and launches a heavily obfuscated Python script again disguised as images.png
T1036.002 — Masquerading: Right-to-Left Override (Defense Evasion)
The infostealer will also attempt to inject a DLL into running instances of browsers such as Chrome, targeting Chrome’s App-Bound Encryption Key to defeat the internal encryption schemes within Chrome.
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
The PXA Stealer payload is then finally injected into browsers to target user credentials and crypto wallets, and to intercecpt targeted data when specific websites are visited.
The PXA Stealer payload is then finally injected into browsers to target user credentials and crypto wallets, and to intercecpt targeted data when specific websites are visited.
T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
Router automatiquement les données volées vers des bots Telegram contrôlés par le groupe
153 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A credential/data-stealing malware family referenced as part of an earlier job-lure campaign whose infrastructure overlaps with Campaign 1. The content does not describe its functionality beyond identifying it as a stealer.
An information-stealing malware family associated in the content with a job-lure campaign and infrastructure/artifact overlap used to link Campaign 1 to a Vietnam-nexus criminal activity cluster.
Python-based infostealer that steals browser session cookies, saved passwords, and autofill data, exfiltrates stolen data to Telegram bots controlled by the operators, and can include remote-access capabilities for control of infected machines via VPS infrastructure.
Stealer malware tied to ad account theft operations targeting Meta Business Manager and Google Ads accounts; linked to a dismantled criminal ring in March 2026.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.