A wave of sophisticated Python-based malware and stealer campaigns has been observed, leveraging advanced evasion techniques and targeting a wide range of platforms. Notable threats include a Python malware that hides within PNG-disguised RAR files and injects payloads into legitimate executables, as well as the Xillen Stealer v4, which employs polymorphic evasion to target over 100 browsers and 70 cryptocurrency wallets, including DevOps environments. Other campaigns involve the Eternidade Stealer, a Python WhatsApp worm using IMAP email for covert command and control and deploying overlays to target Brazilian banking users, and a multi-layer Python RAT distributed via PyPI typosquatting, which bypasses scanners using XOR encryption.
Additionally, attackers are exploiting messaging platforms such as WhatsApp with sophisticated worms that hijack sessions and deploy banking trojans like Astaroth. Another campaign involves a trojanized VPN installer that delivers the NKNShell backdoor, utilizing P2P blockchain and MQTT protocols for covert C2 communications. These incidents highlight the increasing complexity and diversity of Python-based malware, the use of novel distribution and evasion tactics, and the growing risk to both individual users and enterprise environments across multiple vectors, including messaging apps, software supply chains, and browser extensions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
A report described a PyPI typosquatting package used to deliver a multi-layer Python remote access trojan that bypassed scanners with XOR encryption. No distinct earlier event date was given in the source.
Security Online reported on a stealthy Python malware sample concealed in a RAR archive disguised as a PNG file, with payload injection into cvtres.exe. The article focused on the malware's evasion and execution techniques.
A report described Eternidade Stealer as a new Python-based WhatsApp worm that used IMAP email for covert command-and-control and included Brazilian bank overlay functionality. The reference did not specify an earlier discovery date.
Security Online reported on Xillen Stealer v4, describing expanded targeting of more than 100 browsers, 70 cryptocurrency wallets, and DevOps-related data, along with polymorphic evasion features. No separate event date was stated beyond the article publication.
A report detailed a WhatsApp-based worm using a fake "View Once" lure to hijack user sessions and deploy the Astaroth banking trojan. The campaign relied on social engineering to spread and facilitate credential theft.
A Security Online report described a malicious VPN installer used to deploy the NKNShell backdoor, which used peer-to-peer blockchain infrastructure and MQTT for covert command-and-control. No earlier event date was provided in the reference, so the publication date is used as the best estimate.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.