According to PANews, over 170,000 users have been affected by an attack using fake Python infrastructure. The malicious software contains a series of tools designed to steal cryptocurrency wallets from victims' systems. It searches for specific directories associated with each wallet and attempts to steal files related to the wallet. The stolen wallet data is then compressed into ZIP files and uploaded to the attacker's server.
The malware also specifically targets Discord by searching for directories and files related to the platform. It attempts to locate and decrypt Discord Tokens, which can be used for unauthorized access to victims' Discord accounts. In addition to this, the malicious software targets various web browsers, including Opera, Chrome, Brave, Vivaldi, Yandex, and Edge. It searches for specific directories associated with each browser and attempts to steal sensitive data, such as cookies, autofill information, browsing history, bookmarks, credit card information, and login credentials.