< ciso
brief />
Tag Banner

All news with #infostealer tag

403 articles

Agent Tesla v4 uses emoji obfuscation to evade detection

🛡️ KnowBe4 has identified a new Agent Tesla v4 campaign using emoji-based obfuscation and a JScript dropper to bypass detection and steal credentials. The lure leveraged a convincing BEC email spoofing a Philippine bank and instructing finance staff to open an attachment. The dropper embeds Unicode emoji characters to disrupt signature matching, then uses DonutLoader for reflective PE injection so the final binary never touches disk. Researchers advise updating email security and creating YARA rules that combine emoji patterns with JScript function calls to detect the threat.
read more →

ToxicPanda 2.0 and GoldDigger Expand Global Targeting

🛡️ Zimperium zLabs and IBM Trusteer detail updated Android banking trojans: ToxicPanda 2.0 and a new GoldDigger campaign. ToxicPanda now includes 167 remote commands, enhanced PIN-harvesting for over 140 banking and crypto apps, and ADB-based escalation techniques. GoldDigger leverages sophisticated packing and accessibility abuse to drive fraud, with active campaigns in South Africa and the U.K.
read more →

Manic Android malware steals data via nearby devices

🛡️ Manic is a multifaceted Android malware active since at least February that combines spyware, banking fraud, and remote-control features, primarily targeting users in Ukraine and across Europe. It abuses Android Accessibility and notification access to capture PINs, SMS codes, credentials, files, and location, and uses transparent overlays to log keypad input. When direct C2 access is unavailable, Manic can exfiltrate encrypted data through nearby compromised devices over Wi‑Fi Direct or Bluetooth, using multi‑hop relays. Users should avoid installing APKs from untrusted sources, deny Accessibility permissions to untrusted apps, and run Play Protect scans.
read more →

40 Malicious Firefox Extensions Target Web3 Wallets

🛡️ A cluster of 40 malicious Mozilla Firefox extensions has been identified stealing cryptocurrency wallet secrets by impersonating popular Web3 products like OKX, Rabby Wallet, and TronLink. Socket Threat Research attributes the extensions to a broader set of 77 related add-ons with shared code and infrastructure, a campaign they call Offside Wallet Theft Factory, active since March 2026. The threat actors used Supabase projects, Cloudflare Workers, and hard-coded C2 to exfiltrate recovery phrases, private keys, and credentials, often hiding malicious payloads behind benign sports-score or utility shells. Researchers warn the economics of disposable extensions and repurposing identities make the Firefox Add-ons ecosystem an attractive target.
read more →

Hunting MacSync Stealer via behavioral pivots

🔍 Microsoft Defender Experts expanded earlier reporting on MacSync Stealer, a macOS information stealer that rotates infrastructure rapidly. The investigation correlated recurring command-line, request, and upload traits to link over 30 domains and show active staged collection and chunked HTTP PUT exfiltration. The write-up maps payload retrieval, C2 check-in, collection, staging, and cleanup to durable hunting pivots.
read more →

New macOS infostealer hijacks browsers for remote control

🛡️ Jamf Threat Labs uncovered a multi-stage macOS infostealer named AmnesiaStealer that uses a fake GitHub download page to trick victims into running a Terminal command which installs malware. The Rust-based loader retrieves a password-protected ZIP, deploys a universal Mach-O payload and collects passwords, Keychain items, browser data and other sensitive files. A distinct stream_module converts the victim’s Chromium browser into a remotely controlled session via WebSocket, allowing attackers to export cookies and perform browsing actions.
read more →

Infostealers Harvest 1.7 Billion Credentials in H1 2026

🔍 Flashpoint reports 7.4 million devices infected by infostealer malware in H1 2026, marking a 27% increase from the previous half-year. The company recorded 1.7 billion harvested credentials, with Vidar, StealC and Lumma as the top variants, and highlighted a shift to automated credential-processing ecosystems. The report also details rising vulnerability disclosures and growing underground AI-driven threats.
read more →

AmnesiaStealer macOS malware hijacks browser sessions

🛡️ A new macOS infostealer called AmnesiaStealer uses ClickFix campaigns to deliver a Mach-O payload inside a password-protected archive. It copies Chromium profiles and launches hidden, headless browser instances to preserve authentication state while enabling remote operator control. The malware exfiltrates passwords, keychain items, crypto wallets, browser data across 16 Chromium-based browsers, and streams live screencasts and input via WebSocket channels. Researchers at Jamf warn the module abuses the Chrome DevTools Protocol to let attackers navigate and act in victims' authenticated sessions.
read more →

New macOS infostealer spreads via ClickFix lure

🛡️ Researchers at Jamf warn of a Rust-based macOS infostealer named AmnesiaStealer distributed through ClickFix social engineering. The malware harvests credentials, browser data and live sessions, uses OS version–specific bypasses, and includes a remote-controlled second stage to stealthily control Chromium-family browsers. Jamf recommends enabling threat prevention, advanced threat controls and web protection set to Block and Report.
read more →

Jewelbug hacks webmail, runs parallel crypto fraud

🛡️ Symantec attributes a dual campaign to the China-based Jewelbug group, which injected malicious scripts into a shared government webmail installation to compromise 15 tenants. The actors exfiltrated cookies and credentials, deployed the Antino backdoor and browser-stealing extensions, and used a separate infrastructure to run large-scale cryptocurrency fraud. Researchers found ties between espionage tooling and a fraud operation that used AI-generated pages, click-fraud bots, and fake exchange sites.
read more →

AmnesiaStealer targets macOS Chromium sessions

🛡️ Researchers disclosed a new Rust-based macOS infostealer, AmnesiaStealer, delivered via a fake GitHub “Download for macOS” page that tricks users into pasting a Base64 command into Terminal. The multi-stage dropper retrieves a password-protected ZIP and executes a Rust payload that harvests Keychain items, browser data, Apple Notes, Telegram, and files, while using the captured system password for privileged access. A second-stage remote_stream module enables operator-driven browser control over Chromium-family browsers via the Chrome DevTools Protocol to steal live sessions and evade detection.
read more →

Fake CCleaner installer enables Chrome credential theft

🛡️ Researchers discovered a multi-stage Windows malware campaign that uses a fake CCleaner download to install a malicious Chrome extension called GhostDesk. The payload abuses Chrome to capture credentials, cookies, keystrokes, screenshots, and to inject arbitrary JavaScript into active tabs. Variants impersonating 7-Zip and Adobe Acrobat share the same C2 infrastructure and delivery mechanism. Malwarebytes recommends verifying download sources and using up-to-date anti-malware protections.
read more →

Malicious Solidity Pro VS Code Extensions Steal Wallets

🔒 Researchers have identified malicious Visual Studio Code extensions named Solidity Pro that evolved from fetching encrypted payloads to a full-featured information stealer. The extensions, distributed under names like helper-beeps.solidity-pro and web3devtoolsx.solidity-pro, harvest browser profiles, crypto wallets, SSH keys, API tokens, and more, then exfiltrate data via a Telegram bot. The malware uses heavy obfuscation, staged clean releases, and randomized delayed activation to evade detection and marketplace review.
read more →

ClickFix macOS infostealer targets crypto and credentials

🛡️ A Go-based malware delivered via a ClickFix campaign targets macOS users to steal cryptocurrency, browser passwords, Apple Keychain data, and cached credentials. Researchers at Huntress found the attack uses a Bash profiler and Mach-O payload tailored to the victim’s CPU, persists by faking errors with osascript, and removes quarantine flags to bypass Gatekeeper. The malware can intercept and divert crypto transactions and selectively drain a percentage of funds.
read more →

Acoustic Keystroke Recognition Advances and Risks

🔍 A Japanese research team has advanced acoustic keylogging by combining automated keystroke segmentation, clustering, and two-stage language-model inference to map keystroke sounds to characters with minimal training. Their pipeline isolates distinct sounds (notably the spacebar) to define word boundaries, then iteratively refines mappings using dictionaries and manual analyst input. Tests on four laptop models and in noisy or remote settings showed high accuracy with 150–200 keystroke samples, though experiments were limited to lowercase English and excluded numbers.
read more →

Snowflake breach actor pleads guilty in US court

🔒 Connor Riley Moucka pleaded guilty in Seattle federal court to charges including computer fraud, wire fraud and aggravated identity theft for his role in the 2024 Snowflake customer account intrusions that affected at least 165 organizations and exposed data tied to over 100 million people. Prosecutors say attackers used old credentials harvested by infostealer malware and exploited accounts with MFA disabled, resulting in more than $9.5 million in direct victim losses and at least $495,000 personally taken by Moucka.
read more →

macOS ClickFix campaign uses browser fingerprinting

🛡️ Microsoft tracked a macOS ClickFix operation using over 250 front-end domains that fingerprint visitors before deciding whether to show a malware lure. The server-side gate hides malicious pages from crawlers and sandboxes while showing selected Mac users a fake download that ultimately retrieves scripts to launch infostealers such as MacSync and Atomic Stealer (AMOS). The attack still requires users to paste and run an obfuscated Terminal command, and Microsoft recommends users never paste browser instructions into Terminal.
read more →

macOS ClickFix campaign adopts server-side cloaking

🛡️ Microsoft Threat Intelligence tracked a macOS ClickFix campaign distributing infostealers such as MacSync and Atomic Stealer (AMOS) through a large family of look-alike domains. The operation shifted from embedding the malicious ClickFix lure in page HTML to hiding it behind a server-side browser-fingerprinting gate that selectively shows the lure only to visitors resembling genuine macOS browsers. The blog describes domain patterns, fingerprinting checks, infection chain, detection coverage, and hunting pivots defenders can use to find related activity.
read more →

Massive ChainDrop npm supply‑chain attack spreads widely

🛡️ Self‑propagating malware dubbed ChainDrop has compromised over 1,300 npm packages, collectively serving about 2 billion monthly downloads. The attacker gained access by compromising a maintainer’s GitHub account, pushed malicious code to main branches, and used legitimate GitHub Actions workflows to publish tainted releases with valid provenance. The payload uses a Bun runtime to execute an obfuscated infostealer that harvests developer and cloud credentials, then exfiltrates them to a public GitHub repository. Security vendors recommend treating affected workstations and CI/CD runners as compromised, rotating tokens, rebuilding from clean backups, and applying dependency allowlisting and provenance checks.
read more →

Fake Xeno script launcher infects Roblox players

🛡️ Bitdefender identified malicious installers posing as the Xeno Executor Roblox utility that deliver a multi-stage Java-based loader and a final RAT/infostealer. The campaign, active since early this year and spiking in March, lures gamers via forums, Discord, and compromised accounts with archives mimicking legitimate Xeno installations. Once executed, the malware extracts a Java runtime, registers victims with a C2, and deploys payloads that steal browsers, wallets, and account tokens while enabling surveillance and remote control.
read more →