Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accounts — Threadlinqs Intelligence
As of 2026-09-02, Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accounts is a high-severity malware threat attributed to Unattributed Vietnamese-linked threat actor (Vietnam), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-2296 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Unattributed Vietnamese-linked threat actor · Vietnam · FINANCIAL
Netskope Threat Labs documented a new Python NodeStealer variant (August 2026) that expands the long-running Facebook-credential-theft malware family into full spyware, adding keylogging, clipboard
NodeStealer's origins predate the Python family Netskope has tracked since 2023: Palo Alto Networks Unit 42 traces the earliest JavaScript-based NodeStealer sample to a July 2022 compile date, with Meta identifying malicious activity beginning in January 2023 and publicly reporting on the JavaScript variant's Facebook business-account credential and cookie theft in May 2023. In parallel, Unit 42 documented a Python-compiled 'NodeStealer 2.0' campaign that it dates to approximately December 2022 and disclosed in an August 1, 2023 report: two Python variants that layered in MetaMask cryptocurrency-wallet theft, full Facebook account-takeover functionality, a downloader for staging additional malware, and -- in the second variant -- anti-analysis/anti-VM checks and webmail-reading capability, with account-takeover operations routed through the Vietnamese-oriented hotmailbox.me and dongvanfb.net mailbox services.
Python NodeStealer is a credential- and cookie-theft malware family that Netskope Threat Labs has tracked since September 2023, when it targeted Facebook business-account owners via Messenger lures carrying 'defective product' attachments hosted on Facebook's own CDN and on the attacker-controlled domain vuagame[.]store. That original variant stole Login Data, cookies, and 'Local State' encryption keys from Chrome, Microsoft Edge, Brave, Opera, Cốc Cốc, and Firefox, prioritizing Facebook session cookies, and persisted via a batch file dropped into the Windows Startup folder that repeatedly re-launched a Python script named project.py. Stolen data was staged locally, zipped, and exfiltrated over the Telegram Bot API alongside victim IP address, country, and hostname.
In November 2024, Netskope reported a second-generation variant that abused the legitimate Windows Restart Manager library (via windll.LoadLibrary and RmShutdown) to force-close browser processes and unlock database files that would otherwise block credential theft -- a LOLBin technique intended to evade behavioral detection. This variant padded its payload with tens of megabytes of junk code, wrapped the Python script inside batch files that echo it line-by-line into a separate file, added theft of stored credit-card data from the browsers' 'Web Data' SQLite database, and pivoted to hijacking Facebook Ads Manager accounts by generating access tokens from stolen cookies and querying the Graph API for ad account budgets, spend, currency, and country codes. Operators geofenced the malware to exit immediately if the victim's IP-derived country code resolved to Vietnam.
On August 25, 2026, Netskope Threat Labs disclosed a third-generation variant that crosses the malware from an infostealer into full spyware. The new build adds keystroke logging via the pynput library (output written to %TEMP%\\keylog({ip}).txt and transmitted to the attacker's Telegram channel roughly every 120 seconds), clipboard monitoring via pyperclip (captured plain-text clipboard content paired with the victim's IP address), screenshot capture via pyautogui taken at both the start and the completion of malware execution, extraction of saved Wi-Fi passwords, and exfiltration of the victim's Pictures folder. Facebook targeting deepened substantially: the malware now queries more than 20 Graph API endpoints (versus 2 in earlier variants), pulling identity data, the social graph (friends/following/likes), content (posts/groups/events/videos), Pages data, advertising data, commerce/business-manager data, and account-security/login data -- Netskope assesses this is intended to build comprehensive victim profiles that enable account takeovers, impersonation scams, and higher-value resale of the harvested data. Exfiltration now runs through a dual-Telegram-bot architecture -- one bot for general stolen data, a second dedicated to Facebook-specific data -- which Netskope assesses suggests operational specialization or channel redundancy. The compiled .pyc payloads (CPython 3.12+ bytecode) have th
Target sectors: financial services, manufacturing, technology
Target regions: Asia, North America, 039 - Southern Europe
Timeline
- Palo Alto Networks Unit 42 traces the earliest JavaScript-based NodeStealer sample -- the predecessor to the later Python NodeStealer family -- to a July 2022 compile date.
- Unit 42 dates the start of a distinct Python-compiled 'NodeStealer 2.0' campaign to approximately December 2022, running alongside continued use of the original JavaScript variant.
- Meta identifies malicious NodeStealer activity beginning in January 2023, per Unit 42's account of Meta's findings on the JavaScript-based variant targeting Facebook business accounts.
- Meta publicly reports on the original JavaScript-based NodeStealer campaign's theft of Facebook business-account credentials and cookies.
- Palo Alto Networks Unit 42 publishes 'NodeStealer 2.0,' documenting two Python-compiled variants that add MetaMask cryptocurrency-wallet theft, full Facebook account-takeover functionality, a downloader for additional malware, and -- in Variant #2 -- anti-analysis/anti-VM checks and webmail-reading capability; attributes the campaign to a Vietnamese-based actor via Vietnamese code strings, Cốc Cốc browser targeting, and abuse of the hotmailbox.me and dongvanfb.net mailbox services for account-takeover operations.
- Independent reporting (OODA Loop, citing Meta's original findings) attributes NodeStealer to Vietnamese-linked threat actors, citing Vietnamese-language code artifacts and targeting of the Cốc Cốc browser popular in Vietnam.
- Netskope Threat Labs first documents Python-based NodeStealer targeting Facebook business accounts: theft of browser cookies/credentials across Chrome, Edge, Brave, Opera, Cốc Cốc, and Firefox, delivered via Facebook Messenger 'defective product' attachments hosted on Facebook's CDN and vuagame[.]store, persisting via a Startup-folder batch file that relaunches project.py.
- Netskope reports a second-generation NodeStealer variant abusing Windows Restart Manager (RmShutdown) to unlock locked browser database files, padding payloads with tens of megabytes of junk code, wrapping scripts in batch files, adding credit-card theft from the 'Web Data' SQLite database, and pivoting to Facebook Ads Manager account/budget theft; the malware exits if the victim's IP geolocates to Vietnam.
- Netskope Threat Labs discloses a third-generation Python NodeStealer variant with full spyware capabilities -- pynput keylogging, pyperclip clipboard monitoring, pyautogui screenshot capture, Wi-Fi password extraction, and Pictures-folder exfiltration -- an expansion from 2 to 20+ abused Facebook Graph API endpoints, a dual-Telegram-bot exfiltration architecture, .pyc header timestomping, and code artifacts (decorative emoji in log output) indicating LLM-assisted development; targeting led by the financial services sector across Asia and North America.
- Netskope publishes the corresponding IOC set to its public GitHub repository (NetskopeThreatLabsIOCs), including three SHA256 sample hashes, three Telegram bot tokens, three Telegram chat IDs, and staging-file artifact paths for the August 2026 spyware variant.
Detections & IOCs
As of 2026-09-03, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566.003, T1204.002, T1059.003, T1059.006, T1547.001, T1027, T1070.006, T1614, T1082, T1555.003