Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activitydefense-evasion-methodremote-access-implantcommand-and-control-method

Surge in Advanced Python-Based Malware and Stealer Campaigns Targeting Multiple Platforms

Updated 3mo agoFirst seen Nov 24, 20256 sources

A wave of sophisticated Python-based malware and stealer campaigns has been observed, leveraging advanced evasion techniques and targeting a wide range of platforms. Notable threats include a Python malware that hides within PNG-disguised RAR files and injects payloads into legitimate executables, as well as the Xillen Stealer v4, which employs polymorphic evasion to target over 100 browsers and 70 cryptocurrency wallets, including DevOps environments. Other campaigns involve the Eternidade Stealer, a Python WhatsApp worm using IMAP email for covert command and control and deploying overlays to target Brazilian banking users, and a multi-layer Python RAT distributed via PyPI typosquatting, which bypasses scanners using XOR encryption.

Additionally, attackers are exploiting messaging platforms such as WhatsApp with sophisticated worms that hijack sessions and deploy banking trojans like Astaroth. Another campaign involves a trojanized VPN installer that delivers the NKNShell backdoor, utilizing P2P blockchain and MQTT protocols for covert C2 communications. These incidents highlight the increasing complexity and diversity of Python-based malware, the use of novel distribution and evasion tactics, and the growing risk to both individual users and enterprise environments across multiple vectors, including messaging apps, software supply chains, and browser extensions.

Share:
Surge in Advanced Python-Based Malware and Stealer Campaigns Targeting Multiple Platforms
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Nov 24, 20257mo ago

Researchers report PyPI typosquatting campaign delivering Python RAT

A report described a PyPI typosquatting package used to deliver a multi-layer Python remote access trojan that bypassed scanners with XOR encryption. No distinct earlier event date was given in the source.

Researchers detail Python malware hidden in PNG-disguised RAR archive

Security Online reported on a stealthy Python malware sample concealed in a RAR archive disguised as a PNG file, with payload injection into cvtres.exe. The article focused on the malware's evasion and execution techniques.

Researchers identify Eternidade Stealer WhatsApp worm using IMAP for C2

A report described Eternidade Stealer as a new Python-based WhatsApp worm that used IMAP email for covert command-and-control and included Brazilian bank overlay functionality. The reference did not specify an earlier discovery date.

Researchers uncover Xillen Stealer v4 targeting browsers, wallets, and DevOps data

Security Online reported on Xillen Stealer v4, describing expanded targeting of more than 100 browsers, 70 cryptocurrency wallets, and DevOps-related data, along with polymorphic evasion features. No separate event date was stated beyond the article publication.

Researchers disclose WhatsApp worm spreading Astaroth banking trojan

A report detailed a WhatsApp-based worm using a fake "View Once" lure to hijack user sessions and deploy the Astaroth banking trojan. The campaign relied on social engineering to spread and facilitate credential theft.

Nov 22, 20257mo ago

Researchers report trojanized VPN installer delivering NKNShell backdoor

A Security Online report described a malicious VPN installer used to deploy the NKNShell backdoor, which used peer-to-peer blockchain infrastructure and MQTT for covert command-and-control. No earlier event date was provided in the reference, so the publication date is used as the best estimate.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

4 LINKEDOpen in app
Affected products
1 linked
Whatsapp
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Surge in Advanced Python-Based Malware and Stealer Campaigns Targeting Multiple Platforms | Mallory