$ techbeacon▋
Phishing

NodeStealer malware evolves into multi‑function spyware with keylogging and screenshot capabilities

NodeStealer malware evolves into multi‑function spyware with keylogging and screenshot capabilities

A new version of the open‑source NodeStealer tool, originally designed to harvest Facebook account data, has been upgraded with a suite of spying functions that include keylogging, clipboard monitoring, screenshot capture, and broader Facebook profile extraction.

The Python‑based code, which first appeared in security circles as a niche infostealer targeting social‑media credentials, now operates as a more versatile surveillance platform. Researchers who examined the latest release identified modules that record every keystroke entered on the compromised device, take periodic screenshots of the user’s desktop, and silently copy any data placed on the clipboard.

In addition to these capabilities, the updated NodeStealer continues to pull extensive information from victims' Facebook accounts, such as personal details, friend lists, and posted media. By combining credential theft with real‑time observation of user activity, the malware can build a far richer profile of an individual than the original version could achieve.

Security analysts note that the shift reflects a broader trend among low‑cost, community‑maintained malware projects: expanding functionality to increase the value of stolen data for resale on underground markets. While the original NodeStealer was primarily of interest to actors seeking social‑media access, the new keylogging and screenshot features make it attractive to cybercriminals targeting financial fraud, corporate espionage, or blackmail schemes.

Although the code is publicly available on platforms such as GitHub, its distribution is typically hidden within malicious applications, compromised installers, or phishing campaigns that persuade users to run the script on their machines. Once executed, the program runs silently in the background, evading many standard antivirus detections that focus on known signatures rather than behavioral patterns.

Experts recommend that users keep operating systems and software up to date, employ reputable endpoint protection, and avoid executing unknown scripts, especially those downloaded from untrusted sources. As the NodeStealer project continues to evolve, security researchers will monitor its codebase for further enhancements, while law‑enforcement agencies remain alert to potential abuse of the tool in large‑scale data‑theft operations.

Source: GBHackers
Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related