Skip to main content
← All Articles

Tag

#infostealer

23 articles

Advertisement

Phantom Stealer: Fileless Credential Theft & Evasion
HIGH
Malware

Phantom Stealer: Fileless Credential Theft & Evasion

Phantom Stealer uses fileless execution and advanced anti-analysis to steal browser credentials. Learn its TTPs and how to detect this evasive malware.

Runtime Rebel Intel
5 min read·Jun 17, 2026
SU
HIGH
Supply Chain

GitHub Supply Chain Disruption: Microsoft Repos Abused to Host Malware

GitHub recently disabled 73 official Microsoft repositories after they were targeted in a massive campaign pushing password-stealing malware to developers.

Runtime Rebel Intel
4 min read·Jun 9, 2026
MA
HIGH
Malware

Python-Based Infostealer Masked as PDF Targets Browser Credentials

Technical analysis of a PyInstaller-compiled infostealer using Discord webhooks to exfiltrate browser credentials, crypto wallets, and session tokens.

Runtime Rebel Intel
4 min read·Jun 9, 2026
SU
HIGH
Supply Chain

IronWorm Malware: 36 npm Packages Identified in Supply Chain Attack

Security researchers discover a campaign delivering IronWorm infostealer malware via 36 malicious npm packages using preinstall script execution hooks.

Runtime Rebel Intel
3 min read·Jun 4, 2026
MA
HIGH
Malware

Operation Magnus: Dutch Police Disrupt 17 Million Device Botnet

Dutch authorities and international partners seize over 1,200 servers to dismantle the infrastructure behind RedLine and Vidar infostealer malware.

Runtime Rebel Intel
3 min read·May 29, 2026
MA
HIGH
Malware

Analysis of Cross-Platform NPM Stealer Using Discord Webhooks

Technical teardown of an obfuscated Node.js infostealer targeting Discord tokens, crypto wallets, and browser credentials via cross-platform scripts.

Runtime Rebel Intel
3 min read·May 22, 2026
ID
HIGH
Identity & Access

Protecting Identities from Infostealers: Session Hijacking Mitigation

Learn how infostealers like Lumma bypass MFA via session token theft and discover technical strategies for implementing device-bound authentication.

Runtime Rebel Intel
4 min read·May 21, 2026
TH
MEDIUM
Threat Intel

Ukraine Identifies Odesa-Based Infostealer Operator

Ukrainian cyberpolice and US law enforcement identify an 18-year-old in Odesa suspected of compromising 28,000 accounts for dark web monetization.

Runtime Rebel Intel
3 min read·May 21, 2026
SU
HIGH
Supply Chain

Shai-Hulud Infostealer Surfaces in Malicious npm Package Campaign

Leaked Shai-Hulud malware is targeting Node.js developers via malicious npm packages, exfiltrating sensitive data and credentials to Telegram-based C2.

Runtime Rebel Intel
4 min read·May 18, 2026
MA
HIGH
Malware

Malicious Windows 11 ISOs Deliver Vidar Infostealer — Analysis

Security researchers warn of fake Windows 11 ISO installers delivering Vidar and RedLine infostealers through sophisticated DLL side-loading techniques.

Runtime Rebel Intel
4 min read·May 12, 2026
SU
HIGH
Supply Chain

Malicious PyPI Package elementary-data Hijacked for Infostealer

High-profile supply chain attack on the elementary-data PyPI package compromises developer credentials and crypto wallets via account takeover. Patch now.

Runtime Rebel Intel
4 min read·Apr 27, 2026
MA
HIGH
Malware

Python Infostealer Targeting Browser Credentials and Discord Tokens

Technical analysis of a Python-based infostealer leveraging Discord webhooks for exfiltration, targeting browser credentials and session tokens.

Runtime Rebel Intel
4 min read·Apr 21, 2026