UNVEILING A PYTHON STEALER – INF0S3C STEALER
Essential information
- Published
- 03/09/2025 05:35
- Modified
- 03/09/2025 07:04
- Tags
- 2025-09-03 blank grabber data exfiltration discord inf0s3c stealer pyinstaller python stealer system reconnaissance umbral stealer upx packing windows api
- Related entities
- 1 observables, 17 techniques (mitre), 3 malware
Description
Inf0s3c Stealer is a sophisticated Python-based malware designed to collect system information and user data. It systematically gathers host identifiers, CPU information, network configuration, and captures screenshots. The malware enumerates running processes, generates directory views, and compiles stolen data into a password-protected archive for exfiltration. It employs various techniques for persistence, including injection into Discord and Windows Startup manipulation. The stealer targets sensitive information such as passwords, cookies, browsing history, and cryptocurrency wallets. It also implements anti-VM checks and can self-delete after execution. The analysis reveals similarities with other malware projects, suggesting potential for rapid iteration and wider distribution.