Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

PXA Stealer

145
Global rank
146
Month rank
125 infographic chevron week
Week rank
0
IOCs

PXA Stealer is an information-stealing malware that targets individuals and organizations in 60+ countries. It spreads via phishing, archives, and fake software updates. DLL sideloading, decoy documents, and obfuscation help it evade security tools. Exfiltrated data is exfiltrated and monetized through underground marketplaces.

Stealer
Type
Unknown
Origin
1 November, 2024
First seen
13 September, 2026
Last seen

How to analyze PXA Stealer with ANY.RUN

Type
Unknown
Origin
1 November, 2024
First seen
13 September, 2026
Last seen

IOCs

IP addresses
155.102.51.14
163.181.131.226
92.123.104.62
192.178.183.132
150.171.27.11
23.52.181.141
172.66.171.73
149.154.166.110
204.79.197.203
150.171.28.12
212.56.41.77
142.251.110.139
48.209.138.168
150.171.28.11
23.52.181.212
172.67.203.222
162.159.142.9
18.244.18.27
150.171.109.105
142.251.151.119
Hashes
ceebae7b8927a3227e5303cf5e0f1f7b34bb542ad7250ac03fbcde36ec2f1508
226eec4486509917aa336afebd6ff65777b75b65f1fb06891d2a857a9421a974
e383b20484ee90c00054d52dd5af473b2ac9dc50c14d459a579ef5f44271d256
602c4c7482de6479dd2e9793cda275e5e63d773dacd1eca689232ab7008fb4fb
294c97175fd0894093b866e73548ae660aeed0c3cc1e73867eb66e52d34c0dd2
2d1bed2422e131a140087faf1b12b8a46f7de3b6413bae8bc395c06f0d70b9b0
88bdaf4b25b684b0320a2e11d3fe77dddd25e3b17141bd7ed1d63698c480e4ba
5ee3b25676e813d89ed866d03b5c3388567d8307a2a60d1c4a34d938cbadf710
6ac0f1845a56a1a537b9a6d9bcb724dddf3d3a5e61879ae925931b1c0534fbb7
39e13235f87a1b8621ada62c9ad2ebf8e17687c5533658e075efa70a04d5c78d
cb27007e138315b064576c17931280cfe6e6929efc3dafd7171713d204cfc3bf
a462f83ddb0ccc41ac10e0b5b98287b4d89da8bbbca869ccfb81979c70613c6c
d442e5bbb801c004a7903f6c217149fcda521088705ac9fecb0bc3b3058981bf
bc5ed164d15321404bbdcad0d647c322ffab1659462182dbd3945439d9ecbae7
847c14c297dbe4d8517debaa8ed555f3daedf843d6bad1f411598631a0bd3507
ae5d3df23f019455f3edfc3262aac2b00098881f09b9a934c0d26c0ab896700c
abf7d9d1e86de931096c21820bfa4fd70db1f55005d2db4aa674d86200867806
a43a5b58bfc57bd723b12bbdea9f6e1a921360b36d2d52c420f37299788442d3
c39595ddc0095eb4ae9e66db02ee175b31ac3da1f649eb88fa61b911f838f753
0cdb59e255ccd7dcf4af847c9b020aeaee78ce7fcf5f214ebcf123328acf9f24
Domains
client.wns.windows.com
ogads-pa.clients6.google.com
release-assets.githubusercontent.com
qqwwaa.tos-cn-hongkong.volces.com
www.bing.com
update.cg100iii.com
clientapi.aplus.pptv.com
neihite.cc
img-s-msn-com.akamaized.net
drive.usercontent.google.com
ecs.office.com
accounts.google.com
edge.microsoft.com
h.synacast.com
login.live.com
pay.aqiu6.com
crl.microsoft.com
systemformating.rest
config.edge.skype.com
activation-v2.sls.microsoft.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://urlhaus.abuse.ch/downloads/text_online/
http://users.atw.hu/zoolatogato/xruhbmzvlaghfnqcerrv.exe
https://raw.githubusercontent.com/huuuuggga/aaaaa1/refs/heads/main/srtware.exe
https://www.blackhattoolz.com/licensing/updates/addmefast%20bot.exe
https://ossapp.suning.com/pcoss/dl/pptv(pplive)_forap_1084_9993.exe
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://139.198.15.223:8080/pinginfoview.exe
http://haeum.nfile.net/files/haeum.exe
http://ins.pplive.com/config/pptv/qd-all-slient-onelink-autostart/forqd1084/bind_en-us.ini
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://178.16.54.109/1.exe
http://clients2.google.com/time/1/current?cup2key=8:hkp2v16p3z5vxsxlmnunxakw3bzm2k1xceu5qa42qtq&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
http://github.com/vinhuptoday/testbn/raw/refs/heads/main/brbotnet.exe
http://62.60.226.140/files/unique2/file.exe
http://update.cg100iii.com/cgpro/update.exe
http://ocsp.usertrust.com/mfewtzbnmeswstajbgurdgmcgguabbsr83eyjy3njhjvpn5bepfc6mxawqquouejhttpgckwdnrjdtzgnczjy5ocebqer%2bxt6ogbxbkxqbankn0%3d
Last Seen at
Last Seen at

Recent blog posts

post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 1666
comments 0
post image
6 Months on Alert: Get H1 2026 Cyber Risk Rep...
watchers 3504
comments 0
post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 6612
comments 0

PXA Stealer Targeting High-Value Data

Key takeaways

  1. PXA Stealer is an infostealer that primarily targets credentials, browser data, and financial information.
  2. Its methods include DLL sideloading, multi-stage archives, phishing, and legitimate files abuse.
  3. Targeted industries include education and government entities.
  4. Some variants maintain persistence through RAT components or by running alongside legitimate programs.
  5. Stolen information is monetized on underground marketplaces.
  6. Analysts can use ANY.RUN’s Interactive Sandbox to expose PXA Stealer. View analysis in ANY.RUN Sandbox

analysis in Sandbox

PXA Stealer analysis in ANY.RUN’s Interactive Sandbox

  1. Browse data on PXA Stealer in Threat Intelligence Lookup to identify and monitor its variants.

Search results in TI

Overview of PXA Stealer results in TI Lookup

What is PXA Stealer malware?

PXA Stealer is designed to harvest sensitive data through malicious software updates, attachments, and phishing links.

In 2024, a large-scale campaign driven by PXA Stealer unfolded. It was deployed as the final payload successfully stealing high-value data, including credentials and financial data via automated bot networks. Over 4,000 users were impacted by this operation, with 200,000+ passwords stolen.

Threat actors behind the malware are believed to be Vietnamese-speaking cybercriminals, based on code comments and Telegram account data linked to the attack.

The initial sideloading-based distribution through legitimate executables paired with a malicious DLL further evolved to include anti-analysis measures and decoys. The general attack methods haven’t changed. Threat actors demonstrated the ability to improve the malware, refining initial access and obfuscation methods.

Stolen data is subsequently monetized through underground marketplaces.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

PXA Stealer malware technical details

The primary functionality and feature of malware:

PXA Stealer spreads via DLL sideloading and multi-stage payloads in archived files (e.g., Ghost in the Zip campaign).

During 2025, threat actors continued to refine their initial access and evasion techniques. They started to use benign documents (like PDFs) and legitimate software as decoy for more convincing DLL execution. Such elaborate, layered attacks are harder to detect both by endpoint security tools and analysts.

PXA variants are generally not persistence-oriented. Their primary goal is to steal data in one go and exit. However, in several campaigns additional persistence was achieved by extra tools like RAT components. Persistence was also maintained as the malware stayed active alongside the legitimate program that carried the malicious DLL.

Anti-analysis methods include the abuse of legitimate files and software to distract users and analysts. Layered and nested archives, the mixing of benign and malicious objects – all this contributes to the delay of detection.

As for PXA variants that come with RATs, these often include deeper obfuscations, such as multi-layer encoding and fragmented execution stages, making the reconstruction of execution flow even more complex.

For exfiltration of stolen data, PXA uses legitimate cloud messaging platforms, most often Telegram API and controlled C2 infrastructure.

PXA Stealer victimology

A number victims of PXA Stealer are private individuals, but a large proportion are organizations, particularly educational and government organizations from Asian (e.g., South Korea) and European (e.g. Sweden, Denmark, the Netherlands) countries, as well as the US. The total range of victim’s geography includes over 60 countries.

PXA Stealer execution process

See how PXA Stealer attack unfolds in a VM: View analysis in ANY.RUN Sandbox

The attack starts with the delivery of a large archive that contains an .exe file with a malicious DLL library.

PXA Stealer in Sandbox Archived file that includes PXA Stealer as seen in ANY.RUN”s Interactive Sandbox

Upon the execution, the DLL activates and creates a script, which begins to unfold the payload. In particular, the .CMD script uses Windows’ certutil utility to decode and extract an encrypted .RAR archive embedded into a corrupted PDF file.

The next step: certutil extracts base64-coded content from the PDF and transforms it into a new archive file – Invoice.pdf (RAR-archived).

After that, WinRar’s package utility masquerading as images.png file extracts the archive using predefined parameters and password.

PXA Stealer in Sandbox 2 images.png file: the disguised WinRar’s package utility. ANY.RUN’s Sandbox

Now several dependencies for Python environment are unpacked, including a renamed legitimate Python 3.10 interpreter under the disguise of svchost.exe.

PXA Stealer in Sandbox 3 Malicious Python script hidden in images.png. ANY.RUN Sandbox

Finally, the Python script is initialized and sets a Run registry key.

PXA Stealer in Sandbox 4 Malicious Python script initialized. ANY.RUN Sandbox

Once launched, the script proceeds to conduct standard functions of a stealer for data harvesting.

PXA Stealer in Sandbox 5 PXA Stealer-associated data stealing processes. ANY.RUN Sandbox

PXA Stealer malware distribution methods

PXA Stealer is most commonly distributed through:

  • Phishing emails or messages on apps/social platforms

They contain archive attachments, inside of which there’s a legitimate file + a malicious DLL for sideloading. When a user launches the executable, the malicious DLL loads automatically.

  • Download links

Threat actors also use malicious links shared via file-sharing or cloud storage services, as this allows them to bypass email filters.

  • Files shared on corporate networks (user-initiated)

Notably, as PXA Stealer seemed to targeted government and educational institutions, in some cases it was distributed through internal messaging and storage systems.

  • Fake software updates

PXA also spreads through the delivery of legitimate software update files with a malicious DLL in a bundle.

Gathering Threat Intelligence on PXA Stealer Malware

Gain actionable insights on PXA Stealer by browsing Threat Intelligence Lookup that provides:

  • Instant identification of suspicious files, URLs, domains, and IPs linked to PXA Stealer

  • Overview of related IOCs, IOBs, IOAs to facilitate threat hunting

  • Links to live sandbox investigations of PXA Stealer for deeper analysis

  • Insights into C2 connections, exfiltration methods, and distribution techniques

  • Streamlined incident response through immediate access to verified threat intelligence

Follow this link or copy the query to browse TI Lookup:

threatName:"PXA Stealer"

Search results in TI

Overview of PXA Stealer results in TI Lookup

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

PXA Stealer remains high‑risk information‑stealing threat that abuses legitimate executables to evade detection. It exfiltrates credentials, browser data, cookies, and financial information, enabling account takeover, fraud, and further intrusions. Educational and government institutions seems to be especially endangered.

Adopt a proactive defense strategy with ANY.RUN to mitigate the business risks:

  • Analyze suspicious files, archives, and multi‑stage payload chains in sandboxing solutions such as ANY.RUN’s Interactive Sandbox
  • Track emerging PXA Stealer campaigns and strengthen detection across your environment in Threat Intelligence Lookup, a browsable collection of fresh IOCs and IOBs sourced from live investigations by over 15,000 SOC teams.

Get 50 trial request and start gathering actionable intelligence in TI Lookup. Sign up now

HAVE A LOOK AT

Bert Ransomware screenshot
Bert Ransomware is a newly emerged ransomware group that has been active since April 2025. It deploys variants targeting both Windows and Linux systems, focusing on critical sectors like healthcare, technology, and event services across the US, Asia, and Europe.
Read More
DarkVision screenshot
DarkVision
darkvision
DarkVision RAT is a low-cost, modular Remote Access Trojan that gives attackers remote control of infected Windows hosts. Initially observed around 2020 and sold in underground marketplaces, DarkVision has become notable for its full feature set (keylogging, screen capture, file theft, remote command execution and plugin support) and for being distributed via multi-stage loaders in recent campaigns.
Read More
GravityRAT screenshot
GravityRAT
gravity
GravityRAT is a sophisticated spyware and remote access trojan that has been actively targeting organizations and government entities since 2016. It uses innovative anti-analysis techniques and made an evolution from a Windows-only threat to a cross-platform espionage tool capable of compromising Windows, Android, and macOS systems.
Read More
SSLoad screenshot
SSLoad
ssload
SSLoad is a malicious loader or downloader that is used to infiltrate target systems through phishing emails, perform reconnaissance and transmit it back to its operators delivering malicious payloads. To avoid detection, SSLoad employs various encryption methods and delivery techniques highlighting its versatile nature and complexity. It is believed to be a part of Malware-as-a-Service (MaaS) operation given its diverse delivery methods and implemented techniques.
Read More
DarkTortilla screenshot
DarkTortilla
darktortilla
DarkTortilla is a crypter used by attackers to spread harmful software. It can modify system files to stay hidden and active. DarkTortilla is a multi-stage crypter that relies on several components to operate. It is often distributed through phishing sites that look like real services.
Read More
Zloader screenshot
Zloader
zloader trojan loader
Zloader is a banking trojan that uses webinjects and VNC clients to still banking credentials. This Trojan is based on leaked code from 2011, but despite its age, Zloader’s popularity has been only increasing through early 2020, when it relied on COVID-19 themed attacks.
Read More