Since 2023, Netskope Threat Labs has been tracking the Python-based NodeStealer, an infostealer targeting sensitive browser data and Facebook user, and Ads Manager accounts. In August 2026, we found a new variant with major upgrades. Aside from its previous features, it now has full spyware capabilities, including keystroke logging, clipboard monitoring, screenshot capture, and a dual bot Telegram C2 architecture. We suspect these new capabilities were written with AI assistance. Additionally, the malware’s targeting of Facebook data shifts from extracting basic account details to build a much more complex picture of the user managing the accounts, querying more than 20 Facebook Graph API endpoints covering the victim’s identity, social graph, account security, and commerce data. The campaign’s target victims were mainly in Asia and North America, spread across a number of segments, but led by the financial services sector.
Key findings
- Python NodeStealer adds new spyware capabilities
The latest Python NodeStealer variant incorporates new spyware features, including keylogging, clipboard monitoring, and screenshot capture. In addition, it expands its theft targets to include Wi-Fi passwords, the victim’s Pictures folder, and two additional web browsers.- AI assisted upgrade
Newly added code exhibits characteristics consistent with LLM-generated code. This is most prominent in the systematic use of decorative emojis within output logs, a practice absent in previous NodeStealer variants.- Facebook targeting shifts from profiling account to the user managing it
Earlier NodeStealer variants queried only two Facebook Graph API endpoints. The latest variant queries more than 20 endpoints to construct a comprehensive dossier on the individual managing the account, enabling cyberattackers to conduct cross-platform account takeovers, impersonation scams, and higher-value data resale.
