NodeStealer Malware Evolves into Full-Fledged Spyware with Keylogging and Screen Capture
The Python-based information stealer NodeStealer has resurfaced with a significantly upgraded toolkit, now capable of keystroke logging, clipboard monitoring, and screen capture transforming it from a credential thief into a persistent surveillance threat. First identified in 2023, the malware initially targeted browser data and Facebook accounts before expanding to Facebook Ads Manager credentials and payment card details. The latest variant, detected by Netskope researchers in August 2026, primarily impacts victims in Asia and North America, with financial services as the hardest-hit sector, though attacks span multiple industries.
Enhanced Surveillance Capabilities
The most alarming addition is a keylogger leveraging Python’s pynput library to record all keyboard input, storing it in a temporary file before transmitting it to a Telegram command-and-control (C2) channel every two minutes. This exposes passwords, search queries, private messages, and sensitive customer data entered manually. Clipboard monitoring further extends its reach, capturing copied text that may never be typed.
NodeStealer also takes screenshots at execution and termination, sending them via Telegram. These images can reveal dashboards, recovery codes, open documents, and active conversations data that might bypass keyboard or clipboard logging. The malware splits stolen material across two Telegram bots, complicating disruption efforts: one receives browser credentials and cookies, while the other handles Facebook-specific data.
Expanded Facebook Data Theft
The latest version queries over 20 Facebook Graph API endpoints (up from just two in prior iterations), harvesting a comprehensive profile of victims, including:
- Identity details, contacts, and interests
- Posts, pages, and advertising assets
- Business records, integrations, and login data
For organizations running ad campaigns, this access enables unauthorized ad spending, budget theft, and social engineering attacks targeting colleagues. The risk mirrors other malware campaigns exploiting Facebook Ads Manager accounts.
AI-Assisted Development & Evasion Tactics
Netskope’s analysis suggests AI may have assisted in coding the new features, citing repetitive, emoji-labeled API calls a pattern absent in earlier NodeStealer versions. While not definitive proof of a specific tool, it indicates attackers are accelerating development cycles.
The malware is distributed as compiled Python bytecode with altered headers, likely to obscure its origins and hinder automated analysis. Security teams should ensure inspection workflows examine Python bytecode even when metadata appears incomplete.
Defensive Considerations
While the initial infection vector remains unconfirmed, the malware’s post-execution behavior is clear: collect credentials, session data, and screen content to enable fraud, impersonation, or account takeovers. Indicators of compromise (IoCs) include:
- Temporary keystroke log files (e.g., keylog({ip}).txt)
- Unusual Python-based file activity
- Persistent Telegram-bound data exfiltration
The shift from credential theft to continuous surveillance underscores the growing sophistication of information stealers, particularly those abusing legitimate infrastructure like Telegram for C2 operations.
Source: https://cybersecuritynews.com/nodestealer-record-everything/
Facebook for Business cybersecurity rating report: https://www.rankiteo.com/company/facebookforbusiness
Telegram Messenger cybersecurity rating report: https://www.rankiteo.com/company/telegram-messenger
"id": "FACTEL1788539237",
"linkid": "facebookforbusiness, telegram-messenger",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "60",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'industry': ['Financial Services',
'Multiple Industries'],
'location': ['Asia', 'North America'],
'type': 'Organizations'}],
'data_breach': {'data_exfiltration': 'Telegram C2 channels (two separate bots '
'for browser credentials/cookies and '
'Facebook data)',
'file_types_exposed': ['Temporary keystroke log files (e.g., '
'keylog({ip}).txt)'],
'personally_identifiable_information': 'Yes (identity '
'details, contacts, '
'interests, posts, '
'business records)',
'sensitivity_of_data': 'High (PII, financial data, '
'authentication tokens)',
'type_of_data_compromised': ['Credentials',
'Session data',
'PII',
'Payment information',
'Keystrokes',
'Screenshots',
'Clipboard data']},
'date_detected': '2026-08',
'description': 'The Python-based information stealer NodeStealer has '
'resurfaced with upgraded capabilities, including keystroke '
'logging, clipboard monitoring, and screen capture, '
'transforming it from a credential thief into a persistent '
'surveillance threat. The latest variant, detected in August '
'2026, primarily impacts victims in Asia and North America, '
'with financial services as the hardest-hit sector. The '
'malware now queries over 20 Facebook Graph API endpoints to '
'harvest comprehensive victim profiles, enabling unauthorized '
'ad spending, budget theft, and social engineering attacks.',
'impact': {'data_compromised': 'Browser credentials, cookies, Facebook '
'account data (identity details, contacts, '
'interests, posts, pages, advertising assets, '
'business records, integrations, login data), '
'keystrokes, clipboard data, screenshots, '
'payment card details',
'financial_loss': 'Unauthorized ad spending, budget theft',
'identity_theft_risk': 'High (PII, credentials, session data)',
'operational_impact': 'Fraud, impersonation, account takeovers, '
'social engineering attacks',
'payment_information_risk': 'High (payment card details)',
'systems_affected': 'Systems running Python-based malware '
'(compiled bytecode)'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Information stealers are evolving into persistent '
'surveillance tools, leveraging legitimate infrastructure '
'(e.g., Telegram) for C2 operations. AI-assisted '
'development may accelerate malware evolution. Security '
'teams must inspect Python bytecode and monitor for '
'unusual data exfiltration patterns.',
'motivation': 'Financial gain, credential theft, surveillance, fraud, '
'impersonation, account takeovers',
'post_incident_analysis': {'corrective_actions': 'Implement Python bytecode '
'inspection, monitor for '
'Telegram C2 traffic, '
'enhance detection of '
'temporary keystroke log '
'files, and improve user '
'awareness of credential '
'theft risks.',
'root_causes': 'Evolving malware capabilities, '
'abuse of legitimate infrastructure '
'(Telegram), potential AI-assisted '
'development, lack of Python '
'bytecode inspection'},
'recommendations': ['Inspect Python bytecode even when metadata appears '
'incomplete.',
'Monitor for Telegram-bound data exfiltration and '
'temporary keystroke log files.',
'Enhance monitoring for unusual Python-based file '
'activity.',
'Educate users on the risks of credential theft and '
'social engineering attacks targeting Facebook Ads '
'Manager accounts.'],
'references': [{'source': 'Netskope Research'}],
'response': {'enhanced_monitoring': 'Inspection of Python bytecode, '
'monitoring for Telegram-bound data '
'exfiltration',
'third_party_assistance': 'Netskope researchers'},
'title': 'NodeStealer Malware Evolves into Full-Fledged Spyware with '
'Keylogging and Screen Capture',
'type': 'Malware (Information Stealer/Spyware)'}