SolyxImmortal is one of the most interesting and worrying developments in the Windows information-stealing malware space . It is a Python -written threat that does not aim for immediate destruction or mass spread, but rather for discreet, long-term surveillance of users and systems . Its philosophy reflects a broader shift in the cyberattack ecosystem: less “noise,” more patience, and steady collection of valuable data.

Sharp appearance, clear strategy
The emergence of SolyxImmortal in January 2026 did not go unnoticed by security analysts. Unlike many infostealers that aim for quick exploitation and immediate resale of data, this malware is designed as a persistent implant. Its goal is to remain active for long periods of time, recording credentials, keystrokes, documents, and screenshots, without causing any obvious signs of infection.
See also: Pulsar RAT: Execution in memory & HVNC for invisible access to systems
Disguised as a legitimate tool
SolyxImmortal is distributed through deception. The malware is packaged as a seemingly harmless Python script named “Lethalcompany.py”, increasing the chances of it being executed by unsuspecting users. Once activated, it immediately installs persistence and launches multiple surveillance threads in the background.
Interestingly, it does not attempt lateral movement or automatic propagation. Instead, it focuses exclusively on one device, maximizing its duration without attracting the attention of security tools.
Use of legal APIs and platforms
According to Cyfirma, SolyxImmortal extensively leverages legitimate Windows APIs, allowing it to "get lost" in normal system activity. Even more concerning is its use of Discord webhooks as a command-and-control and data extraction mechanism.
See also: PDFSIDER malware is actively exploited by hackers

In this way, attackers exploit the platform’s good reputation, as well as HTTPS encryption, to evade detection at the network level. This is a tactic that is increasingly being seen, with legitimate cloud and communication services becoming “camouflage” for malicious activity.
Persistence mechanisms without administrator rights
SolyxImmortal establishes persistence by copying itself to a hidden location in the AppData, with a name that resembles a genuine Windows component. It then adds an entry to the Run registry key, ensuring automatic execution on every user login.
Notably, the process does not require administrator privileges, which reduces the barriers to infection and increases success in environments with limited privileges.
Targeted theft of credentials from browsers
One of SolyxImmortal's key strengths is stealing credentials from popular browsers, such as Chrome, Edge, Brave, and Opera GX. The malware gains access to the browsers' profile folders, extracts the master encryption keys via Windows DPAPI, and then decrypts the stored login credentials with AES-GCM.
The data is temporarily displayed in plain text, which highlights how vulnerable stored credentials when the attacker has local access to the system.
See also: Researchers exploited a bug in the StealC Malware control panel
Documents, data compression and extraction
In addition to credentials, SolyxImmortal scans the user's home directory for documents with extensions such as .pdf, .docx , and .xlsx. Files are filtered by size to limit network traffic and maintain a low profile.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

All stolen data is compressed into a ZIP file and sent via Discord webhooks to the attackers, completing a fully automated and silent theft cycle.
A threat designed for patience
SolyxImmortal doesn't impress with explosive attacks, but with its operational maturity. Its emphasis on reliability, persistence, and exploitation of legitimate services makes it a typical example of the new generation of spyware , where the real damage is revealed only after valuable data has already been lost . For organizations and ordinary users, it is yet another reminder that the most dangerous threats are often the ones that are invisible.
