This Windows malware is stealing passwords and other data — how to stay safe

A Windows 11 laptop on a desk
(Image credit: Wachiwit / Shutterstock)

Windows PCs are currently under attack from a new Python-based malware that has previously gone undetected which can steal passwords and other sensitive data from victim’s browsers.

According to the the threat analytics company Securonix, this malware is a remote access trojan (RAT) dubbed PY#RATION. It’s currently being spread through a phishing campaign that uses password-protected ZIP files attached to emails that include two .lnk files disguised as images depicting the front and back of a driver’s license.

What sets PY#RATION apart from other Windows malware strains is the fact that it uses the WebSocket protocol to communicate with a command and control (C&C) server where data stolen from infected PCs is sent according to BleepingComputer.

Although new research about this malware has just come to light, researchers at Securonix note that it’s currently being used in attacks and they’ve observed multiple versions of PY#RATION since it launched back in August of last year.

Impersonating Cortana

A picture showing Cortana in the taskbar on a laptop running Windows 10

(Image credit: Shutterstock)

When launched, the two shortcuts contained in the ZIP files execute malicious code in the background while unsuspecting users are looking at the driver’s license images. This code is used to contact the attacker-controlled C&C server and download two text (.txt) files that are then renamed to BAT (.bat) files.

However, the malware also creates “Cortana” and “Cortana/Setup” directories in a victim’s temporary folder. Other executable files are then downloaded, unpacked and run from this location.

PY#RATION is able to establish persistence or a foothold on an infected Windows PC by adding a batch file called “CortanaAssist.bat” in a user’s startup directory. This makes the malware harder to detect as infected users might think it’s a legitimate Windows system file instead of a virus hiding in plain sight.

Although Microsoft’s virtual assistant isn’t nearly as popular as it once was, it’s still included in both Windows 10 and Windows 11. However, in the latest version of Windows, Cortana is no longer pinned to the taskbar. Fortunately, you can also uninstall Cortana if you think Microsoft’s virtual assistant is too invasive.

Stealing browser and clipboard data

The latest version of PY#RATION (1.6.0) contains a number of features to make it easier for hackers to steal data from infected PCs.

For instance, the malware can transfer files to and from a C&C server, record keystrokes, detect if an infected machine is running antivirus software, steal clipboard data and extract both passwords and cookies from web browsers. All of this stolen data can then be used to commit fraud or even identity theft.

Besides stealing data from Google Chrome, Brave, Opera and Microsoft Edge, PY#RATION can also steal info from the best cryptocurrency wallets as well as user and system data from an infected PC. 

How to stay safe from Windows malware

Someone using a laptop securely

(Image credit: NicoElNino / Shutterstock)

Securonix points out that since English is the main language used throughout PY#RATION and the lure images used in this campaign are of a UK driver’s license, the malware is likely being used to target Windows users in the UK or North America.

To stay safe from this and other malware, you should always avoid opening email attachments from unknown senders. While the files inside might seem innocent at first, there could be something malicious going on in the background as is the case here.

Installing one of the best antivirus software solutions can help prevent malware from infecting your PC and many of these programs also feature additional protections against phishing. As for keeping your passwords and other sensitive data secure, you should use one of the best password managers as opposed to storing your passwords in your browser. This way, it will be more difficult for hackers to get their hands on them even if they do manage to infect your computer with malware.

Now that Securonix has shined a light on PY#RATION, we’ll likely find out even more about this new Windows malware including details on the hackers using it in their attacks.

Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs
Malware
New macOS malware uses Apple's own code to quietly steal credentials and personal data — how to stay safe
Mobile malware
New malware uses infected VPN apps to take over your device — here's how to stay safe
A hacker typing quickly on a keyboard
New MassJacker malware is hijacking digital wallets to steal large sums from users
and image of the Google Chrome logo on a laptop
Google Docs under attack from info-stealing malware — how to keep your data and your emails safe
A laptop displaying the Chrome logo
Don't click this — malicious ads impersonating Google Chrome spreading dangerous malware
Latest in Malware & Adware
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs
An FBI agent typing on a computer
FBI issues warning to millions of Americans to avoid these websites that can steal your passwords and banking info
A hacker typing quickly on a keyboard
New MassJacker malware is hijacking digital wallets to steal large sums from users
A person trying to set up a new Wi-Fi router
Thousands of TP-Link routers have been infected by a botnet to spread malware
A smartphone screen displaying the Android name and logo next to a sign reading 'MALWARE'.
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data
Latest in News
Apple Watch Series 10
Future Apple Watch models could get a surprising new feature — what we know
NYTimes Connections
NYT Connections today hints and answers — Monday, March 24 (#652)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #386 (Monday, March 24 2025)
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
  • kep55
    How to protect oneself from this, and other, malware?
    NEVER use Cortana
    Eliminate PEBKAC
    Put brain gear BEFORE engaging fingers on keyboard.
    Don't click on every URL or email that comes your way.
    Refer to method 2.
    Reply