Skip to content

Infostealer

PXA Stealer

aka PXAStealer · PXA

PXA Stealer is an information-stealing malware written in Python, identified by Cisco Talos in an active campaign attributed to a Vietnamese-speaking threat actor (2024, Phan Xuân Anh).

PXA Stealer, also known as PXAStealer, PXA, is a Python infostealer operated by CoralRaider.

Background

PXA Stealer is a Python-based information stealer that Cisco Talos uncovered in an ongoing campaign attributed to a Vietnamese-speaking actor (2024, Phan Xuân Anh). It seeks out sensitive material including online account credentials, VPN and FTP client data, financial details, browser cookies, and gaming-related information. Notably, it can decrypt browser master passwords in order to exfiltrate stored credentials. Delivery and execution rely on heavily obfuscated batch scripts. The operator is tied to the Telegram channel “Mua Bán Scan MINI,” a hub for credential trading and cybercrime, and although there are links to the CoralRaider adversary, that attribution has not been confirmed. During q2 2025, PXA Stealer was seen targeting Italy.


Source: Malpedia (Fraunhofer FKIE).