Python NodeStealer Adds Spyware Features and Expands Facebook Data Theft

Summary
Netskope reports a Python NodeStealer variant with keylogging, clipboard and screenshot capture, expanded Facebook data theft, and separate Telegram bots for stolen browser data and Facebook information. AI assistance is suspected.
Key points
- The latest variant adds persistent keylogging, clipboard monitoring, and screenshot capture, and also steals Wi-Fi passwords and files from the Pictures folder.
- It targets two additional web browsers and queries more than 20 Facebook Graph API endpoints, collecting identity, social, account-security, advertising, and commerce data.
- Two Telegram bots separate stolen browser credentials and cookie databases from Facebook-specific data.
- Netskope suspects AI assistance based on newly added code patterns, including decorative emoji labels; this is an assessment, not confirmed attribution.
- The analyzed compiled Python bytecode has nulled timestamp and file-size header fields, which may mislead researchers or disrupt automated decompilation.
- The campaign mainly targeted victims in Asia and North America, with financial services the leading sector.
Article Details
- Attack Vectors
- The latest NodeStealer variant logs keystrokes, monitors clipboard text, and captures screenshots.
- It steals browser credentials, passwords, and cookie databases; extracts Wi-Fi credentials and the victim’s Pictures directory; and queries more than 20 Facebook Graph API endpoints for personal, social, security, advertising, and commerce data.
- Two Telegram bots separate exfiltration: one receives the primary archive of stolen data, while the other receives Facebook-specific data.
- A compiled .pyc variant carries a CPython 3.12+ magic number but has nulled timestamp and source-size header fields. Netskope Threat Labs says this may mislead researchers or disrupt automated decompilation.
- Netskope Threat Labs suspects the newly added code was AI-assisted, citing consistent emoji-labeled output and method structure absent from earlier samples.
- Defensive Notes
- Inspect Python bytecode even when .pyc header metadata is modified.
- Netskope lists Script-Python.Infostealer, Trojan.Stealer.130, and Trojan.Generic.39958647 as detections.
MITRE ATT&CK
T1005 · Data from Local SystemNodeStealer extracts the victim’s Pictures directory.T1041 · Exfiltration Over C2 ChannelNodeStealer sends stolen data through its Telegram C2 bots, separating the primary archive from Facebook-specific data.T1056.001 · KeyloggingNodeStealer records keyboard presses with pynput and periodically sends the saved keystrokes to its main Telegram C2 bot.T1113 · Screen CaptureNodeStealer uses pyautogui to capture screenshots during execution and sends them to its Telegram C2 bot.T1115 · Clipboard DataNodeStealer uses pyperclip to record plain text pasted to the clipboard and sends it to its Telegram C2 bot.T1539 · Steal Web Session CookieNodeStealer steals browser cookie databases and includes them in its primary exfiltration archive.T1555.003 · Credentials from Web BrowsersThe primary archive sent to NodeStealer’s main Telegram bot contains stolen browser credentials and passwords.
Malware
Vendors
Products
FacebookSince 2023, Netskope Threat Labs has been tracking the Python-based NodeStealer, an infostealer targeting sensitive browser data and Facebook user, and Ads Manager accounts.Facebook Ads ManagerA year later, we observed that it had expanded the data it targets, looking for Facebook Ads Manager accounts and credit card information.Netskope Threat ProtectionNetskope Threat ProtectionTelegramAside from its previous features, it now has full spyware capabilities, including keystroke logging, clipboard monitoring, screenshot capture, and a dual bot Telegram C2 architecture.