Skip to content
PXA Stealer Malware Targets Financial Institutions via Phishing ZIP Files

PXA Stealer Malware Targets Financial Institutions via Phishing ZIP Files

First seen 27 Mar 2026, 11:17 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 28, 2026 at 11:14 UTC

A surge in cyberattacks utilizing PXA Stealer malware has been reported, primarily targeting financial institutions globally. This increase follows the dismantling of major infostealer operations such as Lumma, Rhadamanthys, and RedLine in 2025, which has left a gap in the malware landscape. PXA Stealer is being deployed through phishing ZIP files, making it a significant threat to organizations handling sensitive financial data. Researchers have noted a sharp rise in these campaigns during the first quarter of 2026, indicating a shift in tactics among cybercriminals. Financial firms are urged to enhance their security measures to combat this evolving threat. The current status shows that PXA Stealer is actively being used in the wild, necessitating immediate attention from cybersecurity professionals.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 166d ago How this analysis works

Timeline

2025-01-05
Major infostealer operations Lumma, Rhadamanthys, and RedLine dismantled
2026-01-01
Sharp rise in PXA Stealer campaigns reported
2026-03-27
Current reports highlight ongoing PXA Stealer activity

More articles in this cluster (2)

Following this threat?

Track Lumma in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed