Skip to main content
← All Articles

Tag

#Infostealer

13 articles

Advertisement

MA
HIGH
Malware

ACR Stealer Distributed via Fake Claude AI Desktop Site

Threat actors are distributing ACR Stealer malware through a fraudulent Claude AI desktop application site, targeting browser credentials and crypto wallets.

Runtime Rebel Intel
4 min read·May 26, 2026
MA
HIGH
Malware

SHub macOS Infostealer Spoofs Apple Security Updates, Installs Backdoor

A new SHub macOS infostealer variant employs fake Apple security update prompts via AppleScript to install a backdoor, threatening user data and system integrity.

Runtime Rebel Intel
4 min read·May 19, 2026
SU
HIGH
Supply Chain

Compromised Checkmarx Jenkins Plugin Spreads Infostealer

Official Checkmarx Jenkins AST plugin version 2023.2.7 was compromised with an infostealer, risking credentials and system data. Immediate uninstallation and credential

Runtime Rebel Intel
4 min read·May 12, 2026
Fake OpenAI Privacy Filter Repository Distributes Rust Info-Stealer
HIGH
Supply Chain

Fake OpenAI Privacy Filter Repository Distributes Rust Info-Stealer

A malicious Hugging Face repository impersonating OpenAI's privacy tool reached 244k downloads, delivering a Rust-based information stealer to Windows users.

Runtime Rebel Intel
3 min read·May 11, 2026
TH
HIGH
Threat Intel

Claude.ai Malvertising: How Attackers Abuse Shared Chats for macOS Malware

Threat actors are leveraging Google Ads and legitimate Claude.ai shared chats to distribute macOS infostealers, effectively bypassing traditional web filters.

Runtime Rebel Intel
3 min read·May 10, 2026
SU
HIGH
Supply Chain

Fake OpenAI Hugging Face Repository Distributes Infostealer Malware

Attackers leveraged a fraudulent OpenAI repository on Hugging Face to distribute infostealers. Learn to detect and mitigate these AI supply chain threats.

Runtime Rebel Intel
3 min read·May 9, 2026
Google Chrome ABE Bypass: Heightened Infostealer Threat
HIGH
Threat Intel

Google Chrome ABE Bypass: Heightened Infostealer Threat

VoidStealer Trojan authors bypass Google Chrome's App-Bound Encryption (ABE), enabling infostealers to exfiltrate cookies and credentials from users.

Runtime Rebel Intel
5 min read·May 7, 2026
MA
HIGH
Malware

Storm Infostealer: Bypassing Local Decryption for Session Hijacking

Storm infostealer exfiltrates encrypted browser data for server-side decryption, allowing attackers to bypass MFA and hijack active user sessions.

Runtime Rebel Intel
3 min read·Apr 13, 2026
TH
HIGH
Threat Intel

Alleged RedLine Infostealer Admin Extradited to US

US extradites Hambardzum Minasyan, suspected administrator of RedLine Malware, following Operation Magnus. Analysis of RedLine MaaS and defense strategies.

Runtime Rebel Intel
3 min read·Mar 26, 2026
Trivy Supply Chain Attack Targets CI/CD Secrets in DevOps Workflows
HIGH
Supply Chain

Trivy Supply Chain Attack Targets CI/CD Secrets in DevOps Workflows

A supply chain attack leveraged the Trivy security tool to deploy an infostealer within CI/CD pipelines, compromising cloud credentials and sensitive secrets.

Runtime Rebel Intel
4 min read·Mar 24, 2026
Lumma Stealer Phishing Campaign: Avoiding Copyright Notice Decoys
HIGH
Threat Intel

Lumma Stealer Phishing Campaign: Avoiding Copyright Notice Decoys

Phishing campaign targets healthcare and government sectors with copyright infringement decoys to deliver Lumma Stealer via legitimate cloud services.

Runtime Rebel Intel
3 min read·Mar 23, 2026
Trivy Supply Chain Attack: Malicious Docker Hub Images Identified
CRITICAL
Supply Chain

Trivy Supply Chain Attack: Malicious Docker Hub Images Identified

Attackers hijacked Trivy Docker Hub images (v0.69.4-0.69.6) to distribute infostealers and Kubernetes wipers. Learn how to detect and remediate this threat.

Runtime Rebel Intel
4 min read·Mar 23, 2026