{"id":9993,"date":"2026-01-20T10:03:45","date_gmt":"2026-01-20T10:03:45","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/20\/python-based-malware-solyximmortal-leverages-discord-to-silently-harvest-sensitive-data\/"},"modified":"2026-01-20T10:03:45","modified_gmt":"2026-01-20T10:03:45","slug":"python-based-malware-solyximmortal-leverages-discord-to-silently-harvest-sensitive-data","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/20\/python-based-malware-solyximmortal-leverages-discord-to-silently-harvest-sensitive-data\/","title":{"rendered":"Python-based Malware SolyxImmortal Leverages Discord to Silently Harvest Sensitive Data"},"content":{"rendered":"<p>    Python-based Malware SolyxImmortal Leverages Discord to Silently Harvest Sensitive Data<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>SolyxImmortal represents a notable advancement in information-stealing malware targeting Windows systems. <\/p>\n<p>This Python-based threat combines multiple data theft capabilities into a single, persistent implant designed for long-term surveillance rather than destructive activity. <\/p>\n<p>The malware operates silently in the background, collecting credentials, documents, keystrokes, and screenshots while sending stolen information directly to attackers through Discord webhooks. <\/p>\n<p>Its emergence in January 2026 marks a shift toward stealthier operational models that prioritize continuous <a href=\"https:\/\/cybersecuritynews.com\/postgresql-monitoring-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">monitoring<\/a> over rapid exploitation.<\/p>\n<p>The attack vector centers on distributing the malware, packaged as a legitimate-looking <a href=\"https:\/\/cybersecuritynews.com\/vulnerable-codes-in-legacy-python-packages\/\" target=\"_blank\" rel=\"noreferrer noopener\">Python script<\/a> named \u201cLethalcompany.py,\u201d to target systems. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhr8I-_aHVeWsKgFOzRhM1bTgXVTz6KOtSJeM6VWhfd6TjNmdLN6PPZHN-ZWWeuljOTeJ_703ghjuFqLpkG6d__5N750pxCERsNXVgzE0Zl6M3nkg8Ig7sSvvkgtlHBm1HX6c5SfkK10jr2PfgugViboXp-W1JWpIo-idJCnnjvY5RUVmK3rRAFDbiSSKQ\/s16000\/All%2520execution%2520behaviour%2520is%2520hardcoded%2520%28Source%2520-%2520Cyfirma%29.webp?ssl=1\" alt=\"All execution behaviour is hardcoded (Source - Cyfirma)\"><figcaption class=\"wp-element-caption\">All execution behaviour is hardcoded (Source \u2013 Cyfirma)<\/figcaption><\/figure>\n<\/div>\n<p>Once executed, SolyxImmortal immediately establishes persistence through multiple mechanisms and launches background surveillance threads. <\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> does not spread laterally or propagate itself; instead, it focuses entirely on harvesting data from a single compromised device. <\/p>\n<p>This focused approach enables attackers to maintain long-term visibility into user activity without drawing attention.<\/p>\n<p>Cyfirma analysts <a href=\"https:\/\/www.cyfirma.com\/research\/solyximmortal-python-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> SolyxImmortal as a sophisticated threat that leverages legitimate Windows APIs and trusted platforms for command-and-control communication. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiy4nE2L6BBWIWqePZ1NxuKihscdRWMeqrFy010P-IW8BGYAQvAq89-2pmByROcnUQ2LV2DiHDXfmmh0oWpYE1uyThBIbgK6jwm2XSZdezaDM3-7k0RbneB_yqAplED98mTmJ4Nyxf-AC-VkKenMA8lK9Pj4La3CQSob4b7dGAdTfTC0qT76QG8UrHHvEs\/s16000\/Persistence%2520Mechanism%2520%28Source%2520-%2520Cyfirma%29.webp?ssl=1\" alt=\"Persistence Mechanism (Source - Cyfirma)\"><figcaption class=\"wp-element-caption\">Persistence Mechanism (Source \u2013 Cyfirma)<\/figcaption><\/figure>\n<\/div>\n<p>The malware\u2019s design reflects operational maturity, emphasizing reliability and stealth over complexity. <\/p>\n<p>By utilizing Discord webhooks for data transmission, attackers exploit the platform\u2019s reputation and HTTPS encryption to avoid network-based detection. <\/p>\n<p>This technique demonstrates how threat actors increasingly abuse legitimate services to hide malicious activity.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-persistence-mechanism-and-browser-credential-theft\"><strong>Persistence Mechanism and Browser Credential Theft<\/strong><\/h2>\n<p>The malware establishes persistence by copying itself to a hidden location within the AppData directory, renaming it to resemble a legitimate Windows component. <\/p>\n<p>It then registers itself in the Windows registry Run key, ensuring automatic execution upon each user login without requiring <a href=\"https:\/\/cybersecuritynews.com\/jupyter-misconfiguration-escalate-privileges\/\" target=\"_blank\" rel=\"noreferrer noopener\">administrative privileges<\/a>. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhPtnItdMySYqEQ8NjUBDFzjAhIeJc-6FuCL5aDnU-HbDiRM7wPQbKqZx99kx14uPHrLtmsHQ7-KIBgU5BS8qn7_EvYR8g5nBhvrRulIdiJ_N4vQcBdMI53M9QtsAbarnXNVsWjMupHRjhqQQz3HRnjPlBv-75hwM0QJF5VQiFHlRZKyrFZRxCc4MSoJos\/s16000\/Document%2520and%2520File%2520Harvesting%2520%28Source%2520-%2520Cyfirma%29.webp?ssl=1\" alt=\"Document and File Harvesting (Source - Cyfirma)\"><figcaption class=\"wp-element-caption\">Document and File Harvesting (Source \u2013 Cyfirma)<\/figcaption><\/figure>\n<\/div>\n<p>This approach guarantees continued operation even after system restarts.<\/p>\n<p>SolyxImmortal targets multiple browsers including Chrome, Edge, Brave, and Opera GX by accessing their profile directories. <\/p>\n<p>The malware extracts browser master encryption keys using Windows DPAPI, then decrypts stored credentials through AES-GCM encryption. <\/p>\n<p>Recovered credentials appear in plaintext format before <a href=\"https:\/\/cybersecuritynews.com\/cl0p-ransomware-data-exfiltration-vulnerable\/\" target=\"_blank\" rel=\"noreferrer noopener\">exfiltration<\/a>, indicating minimal local security measures. <\/p>\n<p>The malware also harvests documents by scanning the user\u2019s home directory for files with specific extensions like .pdf, .docx, and .xlsx, filtering results by file size to avoid network overhead. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgH1ozeygPkS4RpDCjZJlPoOFGZq1rEKB9K2802kQm8TJYkIL79qPbKVi-J9-s8GyjuE1okc1ayqPX37k6ZFESnwB4G5Y9C5kna84ErHT_KntOqbRec2z4k0SpIDpz-hd29dNUlvbZ2pW49olcpOoNW_GiUnSYbsW5vUs8H3dH-7ivsyzTw7OlkWKgB4YA\/s16000\/Final%2520data%2520zip%2520file%2520%28Source%2520-%2520Cyfirma%29.webp?ssl=1\" alt=\"Final data zip file (Source - Cyfirma)\"><figcaption class=\"wp-element-caption\">Final data zip file (Source \u2013 Cyfirma)<\/figcaption><\/figure>\n<\/div>\n<p>All stolen artifacts are compressed into a ZIP archive and transmitted to attacker-controlled Discord webhooks, completing the data theft cycle.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/python-based-malware-solyximmortal-leverages-discord\/\">Python-based Malware SolyxImmortal Leverages Discord to Silently Harvest Sensitive Data<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/python-based-malware-solyximmortal-leverages-discord\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Python-based Malware SolyxImmortal Leverages Discord to Silently Harvest Sensitive Data SolyxImmortal represents a notable advancement in information-stealing malware targeting Windows systems. This Python-based threat combines multiple data theft capabilities into a single, persistent implant designed for long-term surveillance rather than destructive activity. The malware operates silently in the background, collecting credentials, documents, keystrokes, and screenshots [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9993","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9993"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9993"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9993\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9993"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9993"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9993"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}