Advertisement
Infostealers Target Anthropic Claude Users via Session Theft
Threat actors are employing various infostealers to compromise Anthropic Claude user accounts via session theft, posing significant risks.
WordlistLoader Evades Detection, Delivers Amatera Infostealer
WordlistLoader uses a novel text-based obfuscation to bypass security, deploying the Amatera infostealer in ClickFix-style campaigns, posing a significant threat.
Critical: Rust `arrayref` Crate Poisoned with Infostealer Malware
Hackers compromised `arrayref`, `append-only-vec`, and `internment` Rust crates to inject infostealer malware, impacting developers and downstream projects.
AmnesiaStealer macOS Malware Hijacks Browser Sessions via Remote Control
AmnesiaStealer targets macOS users via ClickFix attacks, cloning Chromium profiles to enable live remote control of authenticated browser sessions.
Critical npm Supply Chain Attack Delivers Cross-Platform RAT/Infostealer
Critical npm supply chain attack involving nearly 800 malicious packages delivers WEL1DROPPER RAT and infostealer to Windows, macOS, and Linux users.
ClickFix Attack Deploys macOS Infostealer for Crypto Theft
The ClickFix attack leverages a Go-based macOS infostealer to pilfer cryptocurrency, browser data, and Apple Keychain credentials via a Bash script loader.
Advertisement
ChainDrop npm Supply Chain Attack Steals Developer Credentials
Massive ChainDrop npm supply chain attack compromises over 1,300 packages, stealing developer and cloud credentials through malicious preinstall scripts.
Flying Eagle Mobile RAT Builder: China's Infostealer-as-a-Service
Analysis of the 'Flying Eagle' mobile RAT builder, a sophisticated malware-as-a-service platform from China, used by threat groups to deploy infostealers targeting…
JavaScript Smuggling: In-Memory Malware Assembly Evades Defenses
Attackers use JavaScript Smuggling and Blob objects to assemble infostealer malware in-memory, bypassing security filters on fake crypto and trading sites.
AI-Assisted Phishing Leverages WebDAV for Infostealer Deployment
An exposed server revealed an AI-assisted phishing toolkit used in a WebDAV-based infostealer campaign targeting Windows users in Mexico. Learn detection and mitigation.
ACR Stealer Campaign Targets Microsoft Enterprise Credentials
Microsoft warns of a surge in ACR Stealer attacks targeting browser credentials and session tokens to bypass multi-factor authentication in enterprise environments.
North Korean Actors Use SVG Steganography to Deliver OtterCookie
North Korean threat actors are hiding OtterCookie malware in SVG flag images within fake coding tests to target developers and steal cryptocurrency.
OkoBot Framework: Multi-Payload Data & Crypto Theft Attacks
The new OkoBot framework deploys over 20 distinct payloads, primarily targeting cryptocurrency seed phrases, credentials, and sensitive data.
ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops
ClickLock is a new macOS infostealer that terminates essential system processes every 210ms to force users into disclosing their login passwords.
Malicious GitHub Repositories: Infostealer Distribution Threat
Threat actors are leveraging nearly 300 fake GitHub repositories, impersonating legitimate software, to distribute infostealer malware.
Jscrambler npm Package Backdoored with Infostealer Malware
A malicious version of the Jscrambler npm package, 5.0.0-beta-1, was backdoored with infostealer malware, affecting 1,500 downloads. Immediate action needed.
jscrambler 8.14.0 Compromised: Rust Infostealer Supply Chain Attack
The jscrambler 8.14.0 npm release was compromised with a malicious preinstall hook dropping a cross-platform Rust infostealer. Mitigate the threat now.
BusySnake Infostealer Targets Critical Infrastructure: Armored Likho's TTPs
BusySnake infostealer, deployed by Armored Likho, infiltrates critical infrastructure in Russia, Brazil, and Kazakhstan. Understand their TTPs and mitigation strategies.
Djinn Stealer Targets Cloud & AI Credentials via SimpleHelp CVE-2026-48558
Analysis of Djinn Stealer, an infostealer delivered via critical SimpleHelp CVE-2026-48558, targeting cloud and AI development credentials.
Amadey & StealC Malware C2 Infrastructure Disrupted
Microsoft and global allies dismantle the shared C2 infrastructure of Amadey botnet and StealC info-stealer malware, disrupting ongoing cybercrime operations.
Amadey & StealC Malware Operations Disrupted by Operation Endgame
Operation Endgame, led by Europol and Microsoft, has disrupted infrastructure supporting Amadey and StealC info-stealer malware, impacting cybercriminal services.
Phantom Stealer: Fileless Credential Theft & Evasion
Phantom Stealer uses fileless execution and advanced anti-analysis to steal browser credentials. Learn its TTPs and how to detect this evasive malware.
Lumma Stealer Distributed via Fake EditPro AI Image Generator
Threat actors are leveraging a fake AI image generator website to distribute Lumma Stealer malware targeting both Windows and macOS systems.
400+ Arch Linux AUR Packages Hijacked: eBPF Rootkit and Infostealer
Attackers compromised over 400 Arch User Repository (AUR) packages to deploy Rust-based infostealers and eBPF rootkits, targeting developer credentials.