Vietnamese authorities in Thanh Hoa province charged 12 suspects linked to a global malware operation built around PXA Stealer, a Python-based infostealer that allegedly compromised more than 94,000 computers across Europe, the Americas, and Asia. Investigators said the malware campaign was technically led by a self-taught Vietnamese high school student identified only as Nguyen, who reportedly used the Telegram handle "Lone None" and helped develop tooling that harvested browser cookies, saved passwords, and autofill data from infected systems.
Police said the group distributed the malware through mass-email campaigns using executables disguised as PDFs and other routine documents, often packaged in compressed archives and sent with purchased email lists and automated bulk-delivery tools. Stolen data was reportedly exfiltrated through Telegram bots and supported by VPS-hosted infrastructure that also enabled remote access to victim machines; investigators linked the operation to the theft of more than 200,000 credentials and over 4 million browser cookies, and said suspects were charged under Vietnamese laws covering illegal tool production and unlawful access to computer networks and electronic devices.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
A joint SentinelOne and Beazley Security investigation in mid-2025 traced the malware campaigns across 62 countries. The investigation linked the activity to theft of more than 200,000 credentials and collection of over 4 million browser cookies.
Cisco Talos documented the Python-based infostealer PXA Stealer in November 2024. Talos identified targeting in the government and education sectors in Europe and Asia.
The principal developer identified as Nguyen reportedly taught himself Python and C++ beginning in 2023, laying the groundwork for later development of PXA Stealer.
Thanh Hoa provincial police announced charges against 12 suspects tied to a global malware distribution ring centered on PXA Stealer. Authorities said the operation infected more than 94,000 computers worldwide and charged the suspects under Articles 285 and 289 of the Vietnamese Penal Code.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcee.vnexpress.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.