PXA Stealer is a Python-based infostealer first publicly observed in 2024 and associated with Vietnamese-speaking cybercriminal activity. It is designed to harvest sensitive information from Windows systems, including browser-stored credentials, session cookies, autofill data, authentication tokens, financial information, cryptocurrency wallet data, and data from a broad set of desktop applications such as VPN clients, messaging applications, file-transfer tools, password managers, and cloud command-line utilities. Reported campaigns also targeted advertising and social-media account access, including accounts with monetization or administrative value.
Observed delivery chains rely heavily on social engineering. Operators have used phishing and lure-based campaigns, including job-themed approaches on professional networking platforms, mass-email distribution, and archives containing executables disguised as documents. Multiple campaigns used DLL sideloading with legitimate signed software, including document readers and office applications, to launch staged payloads while reducing suspicion. Infection chains commonly unpack a portable Python runtime and execute heavily obfuscated Python scripts, often alongside decoy documents and renamed utilities to hinder analysis.
PXA Stealer has demonstrated browser-focused collection and post-compromise tradecraft beyond simple file theft. It enumerates Chromium- and Gecko-based browsers, decrypts saved passwords and cookies, and in some campaigns injects into running browsers to access protected key material and defeat browser encryption protections. It has also been reported stealing website-specific data related to financial and cryptocurrency services, collecting artifacts from desktop wallets, and accessing application data from tools such as Discord and Telegram. Some reporting also describes interception of data during active browsing sessions.
Exfiltration is strongly tied to Telegram-based operator infrastructure. Stolen data is commonly packaged into archives and sent to Telegram bots or channels, sometimes relayed through intermediary cloud services to obscure the final destination. Campaigns have also used Telegram as part of payload retrieval and operational coordination. Persistence has been observed through Windows Registry Run entries and scheduled tasks masquerading as legitimate update mechanisms. Several campaigns additionally used renamed interpreters, LOLBins, archive utilities, and multi-layer obfuscation for defense evasion.
PXA Stealer has been linked to broad international victimization across dozens of countries. Reported targeting has included government, education, financial institutions, and job seekers, with campaigns also affecting victims in Europe, Asia, and the Americas. The malware is part of a wider ecosystem of Vietnam-linked stealer operations frequently discussed alongside families such as DuckTail, NodeStealer, and VietCredCare. Law-enforcement action in Vietnam in 2026 reportedly disrupted a criminal ring tied to PXA Stealer, but subsequent reporting indicated continued or renewed activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PXA Stealer est un infostealer basé sur Python capable de : Extraire les cookies de session, mots de passe enregistrés et données de remplissage automatique des navigateurs... Router automatiquement les données volées vers des bots Telegram contrôlés par le groupe... Intégrer des outils d’accès à distance permettant le contrôle des machines infectées via des serveurs privés virtuels (VPS).
PXA Stealer est un infostealer basé sur Python capable de : Extraire les cookies de session, mots de passe enregistrés et données de remplissage automatique des navigateurs... Router automatiquement les données volées vers des bots Telegram contrôlés par le groupe... Intégrer des outils d’accès à distance permettant le contrôle des machines infectées via des serveurs privés virtuels (VPS).
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
During a wave of attacks occurring in April 2025, users were phished or otherwise lured into downloading a compressed archive... The large archive attached to the phishing lure contained...
Fichiers exécutables déguisés en PDFs ou documents ordinaires, distribués par campagnes d’e-mails massifs
Threat actors have moved away from purpose-built malicious infrastructure and toward legitimate, high-reputation sending platforms that email security tools are configured to trust. Mimecast’s telemetry shows that among these campaigns, about one in three detections arrived through Salesforce infrastructure, with another quarter delivered through Google Workspace mail-merge tools and SharePoint-hosted links.
Upon execution, the malicious DLL creates a .CMD script Evidence.cmd in the current directory, which orchestrates all subsequent steps in the attack chain... The sideloaded DLL then launches a hidden instance of Command Prompt and begins a multi-stage chain of activity.
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
The infostealer will also attempt to inject a DLL into running instances of browsers such as Chrome, targeting Chrome’s App-Bound Encryption Key to defeat the internal encryption schemes within Chrome.
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
These campaigns use elaborate staging layers that obscure their purpose and delay detection... launches a heavily obfuscated Python script... Once downloaded, the obfuscated Python code is decoded and executed
embedded archives disguised as common file types... a legitimate WinRar executable also hosted in the “-“ folder renamed images.png... The Python interpreter is renamed to svchost.exe and launches a heavily obfuscated Python script again disguised as images.png
T1036.002 — Masquerading: Right-to-Left Override (Defense Evasion)
The infostealer will also attempt to inject a DLL into running instances of browsers such as Chrome, targeting Chrome’s App-Bound Encryption Key to defeat the internal encryption schemes within Chrome.
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
The PXA Stealer payload is then finally injected into browsers to target user credentials and crypto wallets, and to intercecpt targeted data when specific websites are visited.
The PXA Stealer payload is then finally injected into browsers to target user credentials and crypto wallets, and to intercecpt targeted data when specific websites are visited.
T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
Router automatiquement les données volées vers des bots Telegram contrôlés par le groupe
153 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Python-based infostealer that steals browser session cookies, saved passwords, and autofill data, exfiltrates stolen data to Telegram bots controlled by the operators, and can include remote-access capabilities for control of infected machines via VPS infrastructure.
Stealer malware tied to ad account theft operations targeting Meta Business Manager and Google Ads accounts; linked to a dismantled criminal ring in March 2026.
Mentioned only in related coverage as a stealer used in a separate campaign.
Referenced as an associated analytic story; no further details are provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.