Securonix reported a phishing campaign distributing PY#RATION, a Python-based remote access trojan targeting Windows systems through password-protected ZIP archives that contain malicious .lnk shortcut files. Once launched, the malware establishes persistence and gives operators broad access to infected hosts, including remote command execution, keylogging, file transfer, clipboard theft, browser credential and cookie extraction, and host and antivirus enumeration. Newer variants also added network-scanning capability and stronger anti-detection features as the malware evolved from version 1.0 to 1.6.0.
The campaign stood out for using WebSockets through Python Socket.IO for command-and-control and data exfiltration, alongside Fernet-obfuscated Python code to hinder analysis. Securonix linked activity to infrastructure centered on 169.239.129.108, with staged payload delivery from domains including install.realproheros[.]com and Pastebin, and observed status callbacks to api.safeit[.]com. Researchers also noted overlap with a Python-packed infostealer executable named one.exe, indicating the operators were expanding tooling and refining methods to avoid detection.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Securonix observed PY#RATION samples beginning in August 2022, with code marked version 1.0. The campaign used phishing-delivered password-protected ZIP archives containing malicious .lnk files to infect Windows hosts.
Securonix publicly described the PY#RATION campaign as a Python-based remote access trojan using WebSockets for command-and-control and exfiltration. The report detailed its phishing infection chain, persistence, capabilities, and associated infrastructure.
Securonix later identified a PY#RATION payload marked version 1.6.0, indicating the malware was actively developed after the initial August 2022 samples. The newer version added Fernet-obfuscated Python code, sessioning, network scanning, and stronger anti-detection measures.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.