Skip to content
February 8, 2026
Mochiai.blog
Mochiai.blog
Random Article
  • Home
  • Cybersecurity
  • Evolved PXA Stealer wraps PureRAT in multi-layer obfuscation
Categories Cybersecurity

Evolved PXA Stealer wraps PureRAT in multi-layer obfuscation

  • By Shweta Sharma
  • Estimated read time 1 min read
  • September 25, 2025
Evolved PXA Stealer wraps PureRAT in multi-layer obfuscation

PXA Stealer has been around as a Python-based infostealer, tied to the Telegram alias @LoneNone, and previously used for harvesting credentials and browser data.

Commodity malware wrapped in a complex chain

PureRAT itself is not new–it’s a commodity RAT marketed as a remote administration toolkit with features like hidden desktop access (HVNC/HRDP), microphone and webcam spying, registry management, and even cryptowallet monitoring. But what distinguishes the PXA campaign is the elaborate delivery sequence that surrounded it.

The infection began with a phishing lure disguised as a copyright infringement notice, ultimately pulling Python loaders hidden inside renamed executables, Huntress researchers said in a disclosure shared with CSO ahead of its publication on Thursday. Each stage unpacked or decrypted the next, layering Base84, AES, RC4, and XOR encoding on top of one another. Later phases shifted to .NET assemblies that process hallowing and reflective loading to stay under the radar. By the time PureRAT was finally deployed, defenders had to untangle nearly a dozen payloads.

Tags stealer
← Check Point acquires Lakera to build a unified AI security stack → Why Wan2.2-Animate Is the Free Animation Tool You Need to Try Right Now

Loading...

Categories

  • AI Medical
  • AI Reasoning Model
  • Artificial intelligence
  • Best Exam for AI
  • Cybersecurity
  • Machine Learning
  • Programming & Tech
  • Technology
  • Uncategorized
  • VM

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • April 2016

Copyright © 2026
 - Powered by Magze.