Skip to main content
← All Articles

Tag

#Infostealer

68 articles

Advertisement

Infostealers Target Anthropic Claude Users via Session Theft
HIGH
Data Breach

Infostealers Target Anthropic Claude Users via Session Theft

Threat actors are employing various infostealers to compromise Anthropic Claude user accounts via session theft, posing significant risks.

Runtime Rebel Intel
4 min read · Sep 1, 2026
WordlistLoader Evades Detection, Delivers Amatera Infostealer
HIGH
Malware

WordlistLoader Evades Detection, Delivers Amatera Infostealer

WordlistLoader uses a novel text-based obfuscation to bypass security, deploying the Amatera infostealer in ClickFix-style campaigns, posing a significant threat.

Runtime Rebel Intel
4 min read · Aug 25, 2026
HIGH
Supply Chain

Critical: Rust `arrayref` Crate Poisoned with Infostealer Malware

Hackers compromised `arrayref`, `append-only-vec`, and `internment` Rust crates to inject infostealer malware, impacting developers and downstream projects.

Runtime Rebel Intel
4 min read · Aug 21, 2026
HIGH
Malware

AmnesiaStealer macOS Malware Hijacks Browser Sessions via Remote Control

AmnesiaStealer targets macOS users via ClickFix attacks, cloning Chromium profiles to enable live remote control of authenticated browser sessions.

Runtime Rebel Intel
4 min read · Aug 16, 2026
Critical npm Supply Chain Attack Delivers Cross-Platform RAT/Infostealer
HIGH
Supply Chain

Critical npm Supply Chain Attack Delivers Cross-Platform RAT/Infostealer

Critical npm supply chain attack involving nearly 800 malicious packages delivers WEL1DROPPER RAT and infostealer to Windows, macOS, and Linux users.

Runtime Rebel Intel
5 min read · Aug 8, 2026
HIGH
Malware

ClickFix Attack Deploys macOS Infostealer for Crypto Theft

The ClickFix attack leverages a Go-based macOS infostealer to pilfer cryptocurrency, browser data, and Apple Keychain credentials via a Bash script loader.

Runtime Rebel Intel
5 min read · Aug 7, 2026

Advertisement

HIGH
Supply Chain

ChainDrop npm Supply Chain Attack Steals Developer Credentials

Massive ChainDrop npm supply chain attack compromises over 1,300 packages, stealing developer and cloud credentials through malicious preinstall scripts.

Runtime Rebel Intel
4 min read · Aug 4, 2026
Flying Eagle Mobile RAT Builder: China's Infostealer-as-a-Service
HIGH
Malware

Flying Eagle Mobile RAT Builder: China's Infostealer-as-a-Service

Analysis of the 'Flying Eagle' mobile RAT builder, a sophisticated malware-as-a-service platform from China, used by threat groups to deploy infostealers targeting…

Runtime Rebel Intel
4 min read · Jul 30, 2026
MEDIUM
Malware

JavaScript Smuggling: In-Memory Malware Assembly Evades Defenses

Attackers use JavaScript Smuggling and Blob objects to assemble infostealer malware in-memory, bypassing security filters on fake crypto and trading sites.

Runtime Rebel Intel
4 min read · Jul 25, 2026
AI-Assisted Phishing Leverages WebDAV for Infostealer Deployment
HIGH
Malware

AI-Assisted Phishing Leverages WebDAV for Infostealer Deployment

An exposed server revealed an AI-assisted phishing toolkit used in a WebDAV-based infostealer campaign targeting Windows users in Mexico. Learn detection and mitigation.

Runtime Rebel Intel
5 min read · Jul 20, 2026
HIGH
Malware

ACR Stealer Campaign Targets Microsoft Enterprise Credentials

Microsoft warns of a surge in ACR Stealer attacks targeting browser credentials and session tokens to bypass multi-factor authentication in enterprise environments.

Runtime Rebel Intel
3 min read · Jul 18, 2026
North Korean Actors Use SVG Steganography to Deliver OtterCookie
HIGH
Threat Intel

North Korean Actors Use SVG Steganography to Deliver OtterCookie

North Korean threat actors are hiding OtterCookie malware in SVG flag images within fake coding tests to target developers and steal cryptocurrency.

Runtime Rebel Intel
5 min read · Jul 17, 2026
HIGH
Malware

OkoBot Framework: Multi-Payload Data & Crypto Theft Attacks

The new OkoBot framework deploys over 20 distinct payloads, primarily targeting cryptocurrency seed phrases, credentials, and sensitive data.

Runtime Rebel Intel
4 min read · Jul 16, 2026
ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops
HIGH
Malware

ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops

ClickLock is a new macOS infostealer that terminates essential system processes every 210ms to force users into disclosing their login passwords.

Runtime Rebel Intel
3 min read · Jul 16, 2026
HIGH
Malware

Malicious GitHub Repositories: Infostealer Distribution Threat

Threat actors are leveraging nearly 300 fake GitHub repositories, impersonating legitimate software, to distribute infostealer malware.

Runtime Rebel Intel
4 min read · Jul 14, 2026
HIGH
Supply Chain

Jscrambler npm Package Backdoored with Infostealer Malware

A malicious version of the Jscrambler npm package, 5.0.0-beta-1, was backdoored with infostealer malware, affecting 1,500 downloads. Immediate action needed.

Runtime Rebel Intel
4 min read · Jul 13, 2026
jscrambler 8.14.0 Compromised: Rust Infostealer Supply Chain Attack
HIGH
Supply Chain

jscrambler 8.14.0 Compromised: Rust Infostealer Supply Chain Attack

The jscrambler 8.14.0 npm release was compromised with a malicious preinstall hook dropping a cross-platform Rust infostealer. Mitigate the threat now.

Runtime Rebel Intel
4 min read · Jul 11, 2026
BusySnake Infostealer Targets Critical Infrastructure: Armored Likho's TTPs
HIGH
Malware

BusySnake Infostealer Targets Critical Infrastructure: Armored Likho's TTPs

BusySnake infostealer, deployed by Armored Likho, infiltrates critical infrastructure in Russia, Brazil, and Kazakhstan. Understand their TTPs and mitigation strategies.

Runtime Rebel Intel
5 min read · Jul 7, 2026
Djinn Stealer Targets Cloud & AI Credentials via SimpleHelp CVE-2026-48558
HIGH
Malware

Djinn Stealer Targets Cloud & AI Credentials via SimpleHelp CVE-2026-48558

Analysis of Djinn Stealer, an infostealer delivered via critical SimpleHelp CVE-2026-48558, targeting cloud and AI development credentials.

Runtime Rebel Intel
4 min read · Jun 30, 2026
HIGH
Malware

Amadey & StealC Malware C2 Infrastructure Disrupted

Microsoft and global allies dismantle the shared C2 infrastructure of Amadey botnet and StealC info-stealer malware, disrupting ongoing cybercrime operations.

Runtime Rebel Intel
4 min read · Jun 24, 2026
HIGH
Malware

Amadey & StealC Malware Operations Disrupted by Operation Endgame

Operation Endgame, led by Europol and Microsoft, has disrupted infrastructure supporting Amadey and StealC info-stealer malware, impacting cybercriminal services.

Runtime Rebel Intel
5 min read · Jun 24, 2026
Phantom Stealer: Fileless Credential Theft & Evasion
HIGH
Malware

Phantom Stealer: Fileless Credential Theft & Evasion

Phantom Stealer uses fileless execution and advanced anti-analysis to steal browser credentials. Learn its TTPs and how to detect this evasive malware.

Runtime Rebel Intel
5 min read · Jun 17, 2026
HIGH
Malware

Lumma Stealer Distributed via Fake EditPro AI Image Generator

Threat actors are leveraging a fake AI image generator website to distribute Lumma Stealer malware targeting both Windows and macOS systems.

Runtime Rebel Intel
3 min read · Jun 13, 2026
400+ Arch Linux AUR Packages Hijacked: eBPF Rootkit and Infostealer
HIGH
Supply Chain

400+ Arch Linux AUR Packages Hijacked: eBPF Rootkit and Infostealer

Attackers compromised over 400 Arch User Repository (AUR) packages to deploy Rust-based infostealers and eBPF rootkits, targeting developer credentials.

Runtime Rebel Intel
4 min read · Jun 12, 2026