Researchers discovered a new Python-based RAT dubbed PyXie that has been used in campaigns targeting a wide range of industries. Attackers used legitimate LogMeIn and Google binaries to sideload payloads in the first stage of the attack chain, then a second stage malware gathers information on the victim machine, gain persistence. The third stage payload is a downloader dubbed Cobalt Mode, share similarities to the Shifu banking Trojan. The malware is able to download and execute files, update itself, retrieve specific data, perform scans, retrieve screenshots, reboot the system, clear cookies and uninstall itself from the infected system.”]
Source: https://securityaffairs.co/wordpress/94856/malware/pyxie-rat.html