PyXie

Aliases: PyXie RAT

First seen
2019-10-01 00:00:00
Malware type
rat, keylogger, credential-stealer
Family
Malware family
Profile updated
2026-07-07 12:58:20

Targeted industries: healthcare-and-pharmaceutical financial-services government-and-public-sector education-and-nonprofits technology-and-telecommunications

Context

Full-featured Python RAT compiled into an executable. PyXie RAT functionality includes: * Man-in-the-middle (MITM) Interception * Web-injects * Keylogging * Credential harvesting * Network Scanning * Cookie theft * Clearing logs * Recording video * Running arbitrary payloads * Monitoring USB drives and exfiltrating data * WebDav server * Socks5 proxy * Virtual Network Connection (VNC) * Certificate theft * Inventorying software * Enumerating the domain with Sharphound

Reports & references

  • CrowdStrike — Report2021Gtr (report)
  • secureworks.com — Gold Dupont (report)
  • cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
  • CrowdStrike — Carbon Spider Sprite Spider Target Esxi Servers With Ransomware (report)
  • ic3.gov — 211101 (report)
  • Palo Alto Unit 42 — 4 (report)
  • Palo Alto Unit 42 — Vatet Pyxie Defray777 (report)
  • Palo Alto Unit 42 — 3 (report)
  • Palo Alto Unit 42 — 5 (report)
  • Trend Micro — Ransomware Spotlight Ransomexx (report)
  • cluster25.io — A Strange Link Between A Destructive Malware And The Loader Of A Ransomware Group Isaacwiper Vs Vatet (report)
  • Palo Alto Unit 42 — 2 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Pyxie (report)
  • threatvector.cylance.com — Meet Pyxie A Nefarious New Python Rat (report)

External references