Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

SolyxImmortal Malware Abuses Discord to Quietly Harvest Sensitive Information

A novel information-stealing malware, SolyxImmortal, poses a significant threat to Windows users by maintaining persistent surveillance capabilities. This Python-based malware is distributed via underground Telegram channels and exhibits functionalities…

A novel information-stealing malware, SolyxImmortal, poses a significant threat to Windows users by maintaining persistent surveillance capabilities. This Python-based malware is distributed via underground Telegram channels and exhibits functionalities such as credential theft, document harvesting, keystroke logging, and screen capture, all of which operate discreetly in the background.

First detected in January 2026, SolyxImmortal focuses on sustained access, using Discord webhooks for command-and-control communication to bypass traditional network detection. The malware is delivered as a 10.29 KB Python script, "Lethalcompany.py," identified by the SHA-256 hash 5a1b440861ef652cc207158e7e129f0b3a22ed5ef5d2ea5968e1d9eff33017bc. Upon execution, the malware copies itself to the user's AppData directory under a Windows-like filename, marking it as hidden and system-protected. It registers itself under the current user's Run registry key, ensuring automatic execution during each login.

The malware hardcodes two Discord webhook URLs for structured data exfiltration, including credentials and compressed documents, as well as for screenshot transmission. A hardcoded Discord user ID facilitates immediate operator notifications for high-value authentication events.

Credential Harvesting and Surveillance

SolyxImmortal targets Chromium-based browsers by accessing known profile directory paths. It extracts the master encryption key from each browser’s Local State file, decrypting it through the Windows Data Protection API. Saved login credentials are retrieved from browser SQLite databases and decrypted using AES-GCM, producing plaintext username-password pairs for exfiltration.

A novel information-stealing malware, SolyxImmortal, poses a significant threat to Windows users by maintaining persistent surveillance capabilities.
Allison Burke · Thehackingpost

The malware scans the user's home directory for documents with specific extensions while filtering files by size to optimize data collection. Harvested content is compressed into ZIP archives before transmission. Keystroke capture is managed through a persistent keyboard hook, periodically exfiltrating buffered data. The malware also monitors active window titles for keywords related to authentication or financial services, triggering immediate screenshot captures.

Defensive measures should focus on behavioral indicators. Security teams should monitor for process executions from user-writable paths like AppData and TEMP directories, especially when accessing browser credential stores or invoking Windows DPAPI. Unauthorized registry modifications and file compression followed by outbound HTTPS connections are high-confidence detection opportunities.

Advertisement

Organizations are advised to enforce application allowlisting to prevent unauthorized binary execution from user-writable directories and to monitor for repeated HTTPS POST requests initiated by background processes. Strengthening browser credential protection mechanisms and hunting for executables masquerading as legitimate system components within user profile directories can enhance defenses against this malware.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories