Alerts
Events
DCR
Explore Cyware Products
Alerts
Events
DCR
Go to listing page
Ghost in the Zip | New PXA Stealer and Its Telegram-Powered Ecosystem
Malware and Vulnerabilities
August 04, 2025
sentinelone
A sophisticated infostealer campaign leveraging the Python-based PXA Stealer has compromised over 4,000 systems across 62 countries. The campaign exfiltrates credentials, cookies, and financial data via Telegram bots and Cloudflare Workers.
Read More
PXA Stealer
Telegram
Publisher
Previous
Bitdefender Warns Users to Update Dahua Cameras Over Cr ...
Malware and Vulnerabilities
Next
Microsoft Recall can still nab credit cards, passwords, ...
Malware and Vulnerabilities