PyXie
Aliases: PyXie RAT
- First seen
- 2019-10-01 00:00:00
- Malware type
- rat, keylogger, credential-stealer
- Family
- Malware family
- Profile updated
- 2026-07-07 12:58:20
Targeted industries: healthcare-and-pharmaceutical financial-services government-and-public-sector education-and-nonprofits technology-and-telecommunications
Context
Full-featured Python RAT compiled into an executable. PyXie RAT functionality includes: * Man-in-the-middle (MITM) Interception * Web-injects * Keylogging * Credential harvesting * Network Scanning * Cookie theft * Clearing logs * Recording video * Running arbitrary payloads * Monitoring USB drives and exfiltrating data * WebDav server * Socks5 proxy * Virtual Network Connection (VNC) * Certificate theft * Inventorying software * Enumerating the domain with Sharphound
Reports & references
- CrowdStrike — Report2021Gtr (report)
- secureworks.com — Gold Dupont (report)
- cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
- CrowdStrike — Carbon Spider Sprite Spider Target Esxi Servers With Ransomware (report)
- ic3.gov — 211101 (report)
- Palo Alto Unit 42 — 4 (report)
- Palo Alto Unit 42 — Vatet Pyxie Defray777 (report)
- Palo Alto Unit 42 — 3 (report)
- Palo Alto Unit 42 — 5 (report)
- Trend Micro — Ransomware Spotlight Ransomexx (report)
- cluster25.io — A Strange Link Between A Destructive Malware And The Loader Of A Ransomware Group Isaacwiper Vs Vatet (report)
- Palo Alto Unit 42 — 2 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Pyxie (report)
- threatvector.cylance.com — Meet Pyxie A Nefarious New Python Rat (report)