PXA Stealer

Aliases: PXA, PXAStealer

Malware type
credential-stealer
Family
Malware family
Last IoC activity
2026-06-23 20:25:04
Profile updated
2026-07-07 14:40:42

Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality

Targeted regions: country_code:it

Context

PXA Stealer is an information-stealing malware written in Python, identified by Cisco Talos in an active campaign attributed to a Vietnamese-speaking threat actor (2024). The stealer targets sensitive data such as credentials for online accounts, VPN and FTP clients, financial information, browser cookies, and gaming-related data. Notably, PXA Stealer is capable of decrypting browser master passwords to exfiltrate stored credentials. The campaign leverages heavily obfuscated batch scripts for delivery and execution. The actor behind this operation is linked to the Telegram channel “Mua Bán Scan MINI,” known to host credential trade and cybercrime activity. While there are connections to the CoralRaider adversary, attribution to this group remains unconfirmed. In q2 2025 PXA stealer was observed to target Italy.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Py.Pxa Stealer (report)
  • labs.beazley.security — Ghost In The Zip Or New Pxa Stealer And Its Telegram Powered Ecosystem (report)
  • Cisco Talos — New Pxa Stealer (report)
  • darkrym.com — Python Malware Part3 (report)
  • darkrym.com — Pxa Stealers Evolution To Purerat Part 3 Weaponised Python Stage Stage 5 (report)
  • sentinelone.com — Ghost In The Zip New Pxa Stealer And Its Telegram Powered Ecosystem (report)
  • x.com — 1934864757619900789 (report)

External references