Python NodeStealer Adds Spyware Features and Expands Facebook Data Theft

· Original article ↗

Summary

Netskope reports a Python NodeStealer variant with keylogging, clipboard and screenshot capture, expanded Facebook data theft, and separate Telegram bots for stolen browser data and Facebook information. AI assistance is suspected.

Key points

  • The latest variant adds persistent keylogging, clipboard monitoring, and screenshot capture, and also steals Wi-Fi passwords and files from the Pictures folder.
  • It targets two additional web browsers and queries more than 20 Facebook Graph API endpoints, collecting identity, social, account-security, advertising, and commerce data.
  • Two Telegram bots separate stolen browser credentials and cookie databases from Facebook-specific data.
  • Netskope suspects AI assistance based on newly added code patterns, including decorative emoji labels; this is an assessment, not confirmed attribution.
  • The analyzed compiled Python bytecode has nulled timestamp and file-size header fields, which may mislead researchers or disrupt automated decompilation.
  • The campaign mainly targeted victims in Asia and North America, with financial services the leading sector.

Article Details

Attack Vectors
  • The latest NodeStealer variant logs keystrokes, monitors clipboard text, and captures screenshots.
  • It steals browser credentials, passwords, and cookie databases; extracts Wi-Fi credentials and the victim’s Pictures directory; and queries more than 20 Facebook Graph API endpoints for personal, social, security, advertising, and commerce data.
  • Two Telegram bots separate exfiltration: one receives the primary archive of stolen data, while the other receives Facebook-specific data.
  • A compiled .pyc variant carries a CPython 3.12+ magic number but has nulled timestamp and source-size header fields. Netskope Threat Labs says this may mislead researchers or disrupt automated decompilation.
  • Netskope Threat Labs suspects the newly added code was AI-assisted, citing consistent emoji-labeled output and method structure absent from earlier samples.
Defensive Notes
  • Inspect Python bytecode even when .pyc header metadata is modified.
  • Netskope lists Script-Python.Infostealer, Trojan.Stealer.130, and Trojan.Generic.39958647 as detections.

MITRE ATT&CK

Malware

Vendors

Products

Industries

Related Articles