216.73.217.98

Ghost in the Zip | New PXA Stealer and Its Telegram-Powered Ecosystem

· Published 04/08/2025 16:13 · Modified 04/08/2025 21:00

Export JSON

Essential information

Published
04/08/2025 16:13
Modified
04/08/2025 21:00
Tags
2025-08-04 credential harvesting data theft infostealer pxa stealer python telegram
Related entities
5 observables, 14 techniques (mitre), 7 others

Description

SentinelLABS and Beazley Security uncovered a series of campaigns delivering the -based . The malware, which first appeared in late 2024, has evolved to incorporate sophisticated anti-analysis techniques and a hardened command-and-control infrastructure. Over 4,000 unique victim IP addresses from 62 countries were identified, with South Korea, the United States, and the Netherlands being the most targeted. The stolen data includes passwords, credit card records, and browser cookies. The threat actors, linked to Vietnamese-speaking cybercriminal circles, monetize the stolen data through a subscription-based underground ecosystem that automates resale via 's API. The campaign showcases the growing trend of weaponizing legitimate infrastructure for large-scale information theft and monetization.

External references