NodeStealer Malware Steals User Keystrokes and Screenshots
Key Takeaways NodeStealer, a Python-based info-stealer, has evolved into full spyware, now capable of keylogging, clipboard monitoring, and capturing screenshots. The updated malware primarily...
Key Takeaways
- NodeStealer, a Python-based info-stealer, has evolved into full spyware, now capable of keylogging, clipboard monitoring, and capturing screenshots.
- The updated malware primarily targets sensitive browser data, Facebook accounts, Facebook Ads Manager, and payment information.
- Impacted sectors include financial services, with victims largely concentrated in Asia and North America.
- Security researchers at Netskope identified potential AI assistance in the development of the new spyware features.
- The malware leverages Telegram bots for exfiltration, distributing stolen data across two separate channels to hinder disruption.
NodeStealer, a Python-based information-stealing malware, has significantly escalated its capabilities, transforming into a comprehensive spyware tool. Initially focused on pilfering browser data and Facebook credentials, the latest variant now actively records keystrokes, monitors clipboard content, and captures screenshots, enabling continuous surveillance of infected systems.
Table Of Content
This dangerous evolution substantially raises the risk for individuals and organizations whose browsers store critical access information for work, banking, or social media platforms. First identified in 2023, NodeStealer’s scope previously expanded to include Facebook Ads Manager accounts and payment card details. Recent campaigns have predominantly affected victims in Asia and North America, with the financial services sector being a primary target, though the malware has infiltrated diverse industries.
Researchers at Netskope detected this enhanced variant in August 2026, confirming the addition of advanced spyware functionalities to its existing data theft features. In a report, Netskope said that their analysis also uncovered indicators suggesting that portions of the new code may have been generated with the assistance of artificial intelligence.
While the initial infection vector for this upgraded NodeStealer variant remains unconfirmed, organizations are advised against assuming a singular entry point. The malware’s clear objective upon execution is to amass a comprehensive collection of credentials, session data, personal information, and screen captures. This stolen data can then be leveraged for extensive fraud, identity impersonation, or subsequent account takeovers.
NodeStealer Can Now Record Everything Victims Type
A critical new component in NodeStealer is a sophisticated keylogger. This module utilizes Python’s pynput library to meticulously record all keyboard inputs. The captured text is temporarily stored in a file named using the pattern keylog({ip}).txt, where the victim’s IP address is inserted. Every 120 seconds, this accumulated data is transmitted to the primary Telegram command-and-control (C2) channel, after which the temporary file’s contents are erased. This keylogging operation is designed to persist indefinitely.
Such a capability allows attackers to harvest sensitive information, including passwords, search queries, customer data, and private communications, as users type them. Complementing the keylogger, the malware also incorporates clipboard monitoring, enabling it to capture any plain text copied and pasted on the compromised device. This combination provides threat actors with visibility far beyond merely saved browser credentials, akin to techniques seen in other sophisticated keyloggers.
Beyond text-based exfiltration, NodeStealer now captures screenshots. It takes an initial screenshot upon execution and another before its dedicated screenshot function concludes, both of which are then sent via Telegram. These visual captures can expose a wealth of information that might never be entered via keyboard or clipboard, such as sensitive dashboards, multi-factor authentication recovery codes, open documents, and ongoing conversations.
The malware’s operational resilience is further bolstered by its use of two distinct Telegram bots for data exfiltration. One bot receives an archive containing browser credentials, passwords, and cookie databases, while the other is dedicated to Facebook-specific data. This segmented approach to data transmission makes disruption more challenging for defenders, mirroring strategies employed by other forms of Telegram bot-driven malware that exploit legitimate messaging infrastructure for illicit C2 communications.
Facebook Data Theft Expands
The latest NodeStealer samples exhibit a significantly expanded focus on Facebook data, now querying over 20 Facebook Graph API endpoints, a substantial increase from just two in previous versions. This broader reconnaissance goes beyond mere account verification, aiming to construct a detailed profile of the account holder. It seeks information spanning identity details, contacts, interests, posts, pages, advertising assets, business records, integrations, and various login-related data points.
For businesses that manage advertising campaigns on Facebook, this enhanced capability poses a severe threat. Access to business and Ads Manager information could enable attackers to execute unauthorized advertising campaigns, misappropriate advertising budgets, target colleagues with tailored social engineering schemes, or launch highly convincing phishing attacks. This risk mirrors well-documented instances of Facebook advertising account theft observed in other malware campaigns.
Analysts have noted an intriguing development in NodeStealer’s new functionalities: the presence of repeated, consistently structured calls marked with decorative emoji labels. This pattern, absent in earlier versions of the malware, suggests the potential involvement of AI-assisted code generation. While not definitive proof of a specific tool or author, this observation indicates that threat actors may be leveraging AI to accelerate the development of routine features and enhance their malware’s capabilities.
Furthermore, the malware is now distributed as compiled Python bytecode with intentionally altered header fields. This obfuscation technique appears designed to obscure the compilation timeline and potentially hinder automated analysis. Security teams must therefore ensure their inspection workflows are equipped to thoroughly examine Python bytecode, even when its metadata appears incomplete or misleading.
What You Should Do
- Treat any unusual Python-based files, unexpected browser data access attempts, persistent keystroke collection, or archives destined for Telegram as high-priority security alerts.
- Implement the principle of least privilege by limiting administrator access across all systems.
- Ensure all browsers and endpoint protection solutions are consistently updated to their latest versions.
- Regularly review active user sessions on critical platforms and promptly terminate any unfamiliar or suspicious activity.
- Educate staff on the dangers of untrusted attachments and downloads, emphasizing the importance of verifying sources before opening or executing files.
- For individuals managing Facebook business accounts, enable strong multi-factor authentication (MFA) and regularly review connected applications.
- Monitor for any unfamiliar or unauthorized changes to advertising campaigns or business settings on Facebook.
- In the event of a suspected infection, immediately revoke all active sessions and initiate credential resets, particularly for accounts where cookies or session data may have been compromised.
- While stolen screenshots cannot be undone, rapid response and mitigation steps can significantly limit further account abuse and prevent costly misuse of compromised data.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.