Lone None is a Vietnam-linked threat actor associated with information-stealing and online fraud campaigns active since at least late 2024. The actor is tied to the Python-based PXA Stealer, also referred to as Lone None Stealer, and to activity clusters described as the PyChain campaign. Reporting also links Lone None to use of Pure Logs Stealer in related credential and data theft operations. The actor’s operations are characterized by phishing-led malware delivery, extensive abuse of Telegram for staging, command-and-control, and exfiltration, and a strong focus on harvesting browser data, credentials, session cookies, financial information, and cryptocurrency-related assets. Some activity has also prioritized Facebook business and advertising accounts for follow-on abuse or resale. Lone None has been described as Vietnamese-speaking and Vietnam-linked, with malware samples containing Vietnamese-language artifacts and a hard-coded Telegram pseudonym matching the actor name. Separate law-enforcement reporting tied the alias to a malware distribution ring in Vietnam centered on PXA Stealer and attributed technical development to an individual using the Telegram handle “Lone None.” The actor commonly uses phishing emails themed as copyright complaints, legal takedowns, business proposals, recruiting messages, or AI-related lures. Victims are induced to download archive files containing disguised executables or document-themed payloads. Observed intrusion chains include DLL sideloading through legitimately signed binaries, unpacking of bundled Python runtimes, execution of heavily obfuscated Python payloads, and multi-stage retrieval of second-stage components through Telegram bot profiles, URL shorteners, paste-style services, and attacker-controlled infrastructure. Malware associated with Lone None has been observed stealing saved passwords, browser cookies, autofill data, browsing history, host information, credit card data, gaming-related data, and cryptocurrency wallet information. PXA Stealer has also been reported to decrypt browser master passwords and to support remote access to infected systems. In cryptocurrency-focused operations, Lone None Stealer has been reported to monitor and replace copied wallet addresses to divert funds. Targeting has been global, with campaigns observed across Europe, Asia, and other regions, and phishing materials collected in numerous languages. High-confidence sector targeting includes government and education entities. The actor’s tradecraft demonstrates defense evasion through disguised executables, DLL sideloading, staged payload delivery, and use of legitimate platforms and services to blend malicious traffic with normal activity. Known names and related labels include Lone None, LoneNone, lone_none, and the PyChain campaign designation. The actor’s dominant motivation is financial gain, reflected in credential theft, cookie theft, account abuse, cryptocurrency theft, and monetization of stolen access and data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Vietnam-based cybercriminal identity associated with development and operation of the PXA Stealer infostealer distribution network that infected tens of thousands of computers and stole browser credentials, cookies, and other data.
A Vietnam-linked threat actor behind the PyChain campaign, conducting phishing-led intrusions using copyright/legal lures, multilingual decoy content, DLL sideloading, Python-based loaders, Telegram Bot and URL shortener/paste-style multi-stage C2 chains, and credential/cryptocurrency wallet theft.
Associated with Pure Logs Stealer activity; uses Telegram Bot API for C2/data exfiltration (stolen credentials and host info) and has also used Telegram bot profile content to provide second-stage payload URL components (leading to a paste.rs-hosted Python script).
Lone None is conducting a global phishing campaign using fake legal takedown notices to deliver information-stealing malware, with a particular focus on cryptocurrency theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.