A Vietnamese-speaking cybercriminal operation is distributing the Python-based PXA Stealer through phishing ZIP archives disguised as documents. The archives use hidden and system file attributes to obscure their contents and include renamed, legitimately signed executables—including Microsoft Word 2013, winword.exe, Haihaisoft PDF Reader, and WinRAR—used to DLL-side-load malicious payloads. In one execution chain, a renamed Microsoft-signed winword.exe loads a malicious AppvIsvSubsystems64.dll, which reconstructs a subsequent command from a padded Korean-named document; a WinRAR binary masquerading as a PNG then extracts further components. The operators also stage a signed Python interpreter as C:\Users\Public\Windows\svchost.exe and use obfuscated Python code to hinder detection and sandbox analysis.
PXA Stealer collects browser passwords, cookies, autofill and payment-card data, authentication tokens, cryptocurrency-wallet information, and other application data. Stolen data is routed through Cloudflare Workers and related intermediary infrastructure to Telegram bots and channels, supporting a broader Telegram-based criminal ecosystem associated with Sherlock-related services that resell and reuse compromised information. Researchers identified more than 4,000 victim IP addresses in 62 countries, with South Korea, the United States, the Netherlands, Hungary, and Austria among the most affected; Cloudflare was notified and disrupted reported malicious Worker infrastructure.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
A July 2025 PXA Stealer wave used a signed Microsoft Word 2013 executable with a malicious msvcr100.dll for DLL sideloading. It displayed a fake copyright-infringement notice in a benign Tax-Invoice-EV.docx decoy, decoded and extracted an archive, then ran a Python payload with browser-injection capabilities.
An April 2025 campaign wave used a signed Haihaisoft PDF Reader executable and a malicious DLL for sideloading, establishing persistence and retrieving further payloads from Dropbox. The wave delivered LummaC2 and Rhadamanthys Stealer and used certutil, a malformed PDF with an embedded encrypted RAR archive, renamed WinRAR, and a renamed Python interpreter.
The Python-based PXA Stealer campaign became active in late 2024; some associated Telegram BotIDs were created as early as October 2024. The operators were assessed as linked to Vietnamese-speaking cybercriminal circles.
Researchers notified Cloudflare that the campaign was abusing Cloudflare Workers as relays for Telegram-based data exfiltration. Cloudflare took action to disrupt the reported infrastructure.
A phishing campaign used ZIP archives masquerading as document downloads to sideload a malicious AppvIsvSubsystems64.dll through a renamed, signed winword.exe. The chain used a WinRAR executable disguised as a PNG and staged a signed Python interpreter as C:\Users\Public\Windows\svchost.exe, with a PYMEOMEO-obfuscated Python payload.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 95 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourcecommunity.fortinet.com
Open sourcelab52.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.