#infostealer

19 posts · Last used 2d

Back to Timeline
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 2d ago
Microsoft warns of rising ACR Stealer attacks using ClickFix lures to steal browser credentials and tokens from enterprises. Two chains detailed. #ACRStealer #ClickFix #Infostealer #Malware #Cybersecurity http://securityonline.info/acr-stealer-clickfix/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
sekurak News @sekurakbot@mastodon.com.pl · 3d ago
BusySnake – stealer atakujący cele o znaczeniu krytycznym w Rosji. Za kampanię odpowiada grupa APT Armored Likho Badacze bezpieczeństwa za pośrednictwem portalu Securelist poinformowali o wykryciu nowej kampanii phishingowej powiązanej z nieznaną dotąd grupą APT (nazwaną przez analityków Armored Likho). Wszelkie poszlaki wskazują, że grupa ta jest również znana pod nazwą Eagle Werewolf. Jej celem są przede wszystkim instytucje rządowe oraz przedsiębiorstwa z sektora krytycznego w Rosji,... #Aktualności #Apt #Infostealer #Phishing #Rosja https://sekurak.pl/busysnake-stealer-atakujacy-cele-o-znaczeniu-krytycznym-w-rosji-za-kampanie-odpowiada-grupa-apt-armored-likho/
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 19, 2026
🤖 Microsoft warns of surge in ACR Stealer attacks: infostealer targets browser-stored passwords, auth tokens, and sensitive documents from enterprise environments. Active campaigns observed. 🔗 https://www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers/ #Malware #Infostealer #CyberSec
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 18, 2026
🤖 Microsoft warns of surge in ACR Stealer attacks targeting enterprise customers. Malware steals browser-stored passwords, auth tokens, and sensitive documents. Active campaign observed. 🔗 https://www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers/ #Malware #InfoStealer #CyberSec
0
0
0
Jamf Threat Labs @jamfthreatlabs@bird.makeup · Jul 13, 2026
Meet CrashStealer. This one takes delivery more seriously than most, a signed and Apple-notarized dropper that's pulling its second stage payload down through GitHub. The payload is a native C++ stealer with client-side AES-GCM encryption and layered anti-analysis. Check out our writeup for additional details and indicators of compromise. https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/ #infostealer #malware #macos #threatresearch
1107
0
20
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 17, 2026
Arctic Wolf found 292 fake GitHub repositories impersonating software vendors to deliver a BoryptGrab-lineage infostealer via DLL side-loading. #GitHub #BoryptGrab #Infostealer #Malware #ArcticWolf http://securityonline.info/fake-github-repositories-boryptgrab/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 16, 2026
🤖 AsyncAPI npm packages compromised in supply-chain attack. Five malicious versions of @asyncapi/* packages published to npm, delivering a RAT with credential-stealing capabilities. 🔗 https://www.bleepingcomputer.com/news/security/-asyncapi-npm-packages-infected-with-credential-stealing-malware/ #SupplyChain #Malware #InfoStealer #CyberSec
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 15, 2026
A malicious Go module exposed a GitHub lure network of 222 repositories, dubbed Operation Muck and Load, staging RATs and infostealers. #GoModule #SupplyChain #GitHub #Malware #InfoStealer #AsyncRAT #DevSecOps #InfoSec https://securityonline.info/malicious-go-module-lure-network/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
The New Oil @thenewoil@mastodon.thenewoil.org · Jul 14, 2026
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 12, 2026
🤖 Compromised jscrambler 8.14.0 npm release drops a Rust infostealer during install. The malicious preinstall hook executes a native binary on Windows, macOS, and Linux. Socket's security scanner flagged the release within 6 minutes of publication. 🔗 https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html #SupplyChain #Infostealer #npm #CyberSec
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 11, 2026
🤖 Supply chain attack: jscrambler 8.14.0 npm package compromised. Installing it runs a Rust infostealer via a preinstall hook — native binaries for Windows, macOS, and Linux. Socket detected the threat within 6 minutes. 🔗 https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html #SupplyChain #Infostealer #CyberSec
0
0
0
Grub :verified: :linux: :gnu: @Grub_09@mastodon.uno · Jul 07, 2026
PamStealer:infostealer per macOS con funzionalità avanzate I ricercatori dei Jamf Threat Labs hanno individuato un nuovo #infostealer per #macos con funzionalità più avanzate rispetto a simili #malware PamStealer viene distribuito tramite una versione fasulla di Maccy (noto clipboard manager) e sfrutta l’interfaccia PAM (Pluggable Authentication Modules) del sistema operativo per validare la password dell’utente prima di inviarla al server remoto. @sicurezza #pamstealer https://www.punto-informatico.it/pamstealer-infostealer-macos-funzionalita-avanzate/
4
0
4
The New Oil @thenewoil@mastodon.thenewoil.org · Jul 04, 2026
0
0
3
hasamba @hasamba@infosec.exchange · Jul 03, 2026
---------------- 🦠 Malware Analysis =================== KuinaExtractor: Six Months of a Rust Infostealer's Evolution ThreatRay published a detailed analysis tracking a Rust-based infostealer family across four major build iterations and two parallel experiments from December 2025 through June 2026. December 2025 — First Build The earliest builds were already full-featured: Chrome v20 App-Bound-Encryption bypass via LSASS impersonation for master key recovery, theft of Roblox cookies, Steam sessions, crypto wallets, and Discord tokens. Exfiltration used a Discord webhook. Privilege escalation relied on a single fodhelper/ms-settings UAC bypass. GitHub served as both CDN and disposable VPS/RDP infrastructure via GitHub Actions. January 2026 — Rewrite A rapid rebuild added substantial reconnaissance: eight WMIC hardware queries, WiFi SSID enumeration, Windows Credential Manager dump, a routine terminating 17 browser processes, victim-IP geolocation, and a loop disabling Microsoft Defender. Exfiltration shifted to a Telegram bot. The single UAC bypass was replaced by a function-pointer table with seven methods. March 2026 — Production Hardening The cookie-theft mechanism remained (LSASS/ABE chain, extended with ChaCha20-Poly1305 for newer Chrome versions). UAC bypass moved to SilentCleanup. Browser coverage grew to roughly 40 targets including CocCoc. Broad VM and sandbox detection was added. This variant is still observed today. June 2026 — "k0to" Rebrand The build dropped the "Kuina" name and shifted focus to concealment. It uses a self-contained HTTP stack (reqwest over hyper and rustls) with its own CA roots, 28-byte XOR string wrapping including the Telegram C2 URL, and scans PowerShell window titles for analyst tools. The Telegram channel is push-only. Parallel Experiments • KuinaCookieExtractor (January): Leaner codebase, Discord webhook exfiltration, lighter anti-analysis (logs VM warning and continues). Linked to same author via kuina build user, KUINA_UAC_BYPASS_ATTEMPTED sentinel, and kuina1999 handle. Disappeared after two weeks. • Zenith (April-May): Short-lived C2 experiment. Debug build shipped with verbose [DEBUG] traces to zenith_debug.txt, including author self-attribution. Mutex disguised as network adapter name. Panel at 103.229.53[.]18:3000 (Vietnamese AS135918). Abandoned within days. The developer iterates quickly and learns from deployment feedback. The self-contained TLS stack and XOR wrapping in k0to indicate awareness of network-based detection signatures. 🔹 KuinaExtractor #infostealer #malware_analysis #Rust #threat_intelligence 🔗 Source: https://www.threatray.com/blog/kuinaextractor-six-months-of-a-rust-infostealers-evolution
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jun 30, 2026
🤖 Malicious Chrome extension impersonating Perplexity AI intercepted all searches and URL bar input, routing queries through an attacker-controlled server. Microsoft uncovered it; Google removed it from the store after disclosure. 🔗 https://thehackernews.com/2026/06/malicious-perplexity-chrome-extension.html #Chrome #Infostealer #CyberSec
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jun 30, 2026
🤖 CVE-2026-48558 (CVSS 9.8): Critical auth bypass in SimpleHelp RMM exploited to deliver 'Djinn' infostealer targeting cloud & AI credentials. Chains SimpleHelp RCE with credential harvesting from dev/admin environments. 🔗 https://www.darkreading.com/cyberattacks-data-breaches/djinn-stealer-targets-cloud-ai-credentials #CVE #Infostealer #CloudSec #CyberSec
0
0
0
RelayShieldAdmin @relayshieldadmin@infosec.exchange · Jun 12, 2026
11.1 million devices infected with infostealers in 2025. 3.3 billion credentials now circulating in criminal markets. Vidar surged to 73% of infected hosts by early 2026. Lumma dropped to 1.1%. The ecosystem rotates tools faster than detection catches up. MaaS entry point: $60/month. Less than most SaaS subscriptions. The ransomware connection that gets overlooked: stolen VPN/RDP credentials are how attackers enter the perimeter as legitimate users, weeks before the payload fires. Full breakdown: https://relayshield.hashnode.dev/infostealers-credential-theft-2025 #infosec #infostealer #malware #threatintel #ransomware #cybersecurity
0
1
0