< ciso
brief />
Tag Banner

All news with #infostealer tag

423 articles

UAC-0099 Deploys ASHVEIN .NET Infostealer Against Ukraine

🛡️ TrendAI attributes a previously undocumented .NET infostealer and RAT named ASHVEIN (aka TelemetryBrowser) to the Russia-aligned actor UAC-0099, used in operations targeting Ukrainian government personnel. The malware combines credential theft from Chrome and Firefox, GDI-based screenshots, file collection, PowerShell remote shells, system fingerprinting, and encrypted C2 communications, with delivery via DLL sideloading, VHD containers, and .NET droppers. UAC-0099 has evolved from PowerShell- and Go-based tools to C# and .NET-protected binaries and has expanded targeting to logistics and civilian infrastructure.
read more →

Tensorlake npm Package Compromised in ChainDrop Attack

🔒 The npm package tensorlake, a TypeScript SDK for Tensorlake applications and cloud services, was compromised in a ChainDrop / Shai-Hulud supply chain attack after a malicious 0.5.144 release was published. The trojanized release used a preinstall hook and an obfuscated Bun-based loader to deploy a credential-stealing worm that harvests secrets, drops additional malware, establishes persistence, and enables remote code execution. Affected users are urged to remove the package and rotate exposed credentials.
read more →

RatHat C2 evolves into malware-as-a-service hub

🔍 Research shows the RatHat Android banking trojan's backend evolved far more than the implant itself, with successive C2 panels that can build malware, manage infected devices and use AI to prioritize victims. Cleafy observed three panel generations and a rebrand from BlackCat to Panda Workshop between late 2025 and September 2026, with nearly 100 deployments since April 2026. Panels now support operator 2FA, phishing page builders, role-based accounts and the ability to deploy a native Go service for shell-level persistence outside app permissions.
read more →

RatHat Android banking trojan console exposed

🛡️ Cleafy links the RatHat Android banking trojan to a web-based control console used in nearly 100 deployments since April 2026. The console stores stolen data from infected phones and can build, sign, and publish malicious apps automatically. Its latest variant uses Google's Gemini AI to estimate victims' bank balances and prioritize high-value targets. Operators gain one-click shell access via ADB and a Go-based agent that streams the screen without permission prompts on older Android versions.
read more →

Lunex Stealer abuse of AMD driver escalates threat

🛡️ Ontinue details a four-stage attack chain distributing Psychedelic (LunexStealer) via compromised Ukrainian sites using ClickFix-like CAPTCHA lures. The chain uses bogus MSI installers to deploy LunexLoader, bypass UAC, and leverage a vulnerable AMD Radeon driver (PDFWKRNL.sys, CVE-2023-20598) for BYOVD-based defense evasion before installing a PowerShell-backed native messaging host. The stealer harvests browser credentials, cookies, and desktop and extension cryptocurrency wallets while persisting via registry, scheduled tasks, and a malicious Chrome extension.
read more →

MacSync uses iCloud calendars to load payloads

📌 A new MacSync variant for macOS now leverages public iCloud calendar events to deliver follow-on payloads. Kaspersky found the Swift-based infostealer being distributed via ClickFix-style social engineering and fake apps, with a downloader extracting commands from calendar DESCRIPTION fields to fetch archives hosted on iCloud. The malware retains broad credential-stealing capabilities and added an Objective-C backdoor that persists via LaunchAgents, .zshrc changes, and Git hooks.
read more →

ClickFix campaign injects fake Cloudflare lures

🛡️ Arctic Wolf Labs and Blackpoint Cyber reported an active ClickFix campaign compromising Ukrainian business websites to serve bogus Cloudflare verification pages that trick victims into executing an MSI installer. The MSI chain delivers a newly observed information stealer called Psychedelic, which harvests browser credentials, tokens, and crypto-wallet data, sets persistence, and contacts a C2 for follow-on tasks. Researchers also linked the ClickFix chain to other payloads including RemotePanel and BoundSiphon, highlighting modular remote-access and data-theft capabilities and evidence pointing to likely Russian-speaking operators.
read more →

SectopRAT variant hidden in legitimate Windows software

🛡️ The FortiGuard Incident Response team investigated a Windows intrusion where a SectopRAT .NET RAT was concealed inside a legitimate audio application. The malware used a tampered DLL and a multi-stage loader that extracted an encrypted payload from a DB file, initialized the .NET runtime in memory, and executed a heavily obfuscated RAT. The variant communicates over AES-encrypted channels with a hardcoded C2 and backup domains, supports 29 control commands, and steals browser, email, gaming, and cryptocurrency wallet credentials.
read more →

Malicious npm Package Masquerades as Twilio Probe

🛡️ ReversingLabs disclosed a malicious npm package named tw-pkgprobe-7731 that posed as a security probe for developers integrating Twilio. First published in mid-August 2026 with multiple rapid versions, the package checks for Twilio environments, harvests environment variables and system details, and exfiltrates data via webhook. Some versions specifically targeted Twilio SIDs and could steal ACCOUNT_SID and AUTH_TOKEN, while later releases reverted to benign probing and OSINT collection.
read more →

Malicious npm package hides runtime payloads

🛡️ Checkmarx has identified a malicious npm package, indexed-btree, that concealed its payload inside application code rather than using lifecycle scripts, indicating attackers are adapting to npm's install-time protections. The package, first published on June 18, 2026, accumulated millions of downloads before removal and is estimated to have generated roughly €230,933.57 in cryptocurrency for the operator. The loader was embedded in a BTree.prototype.set() method and used EtherHiding and blockchain-hosted encrypted blobs to fetch staged payloads before cleaning up traces.
read more →

KREMLIN malware forces browser extension installs

🔒 Researchers at Elastic Security Labs uncovered a banking malware toolkit called KREMLIN that has been active since mid-2025 and installs malicious Chrome and Edge extensions to steal credentials, session tokens, and other sensitive data. The infection begins with a malicious JavaScript file posing as banking documents, which downloads Node.js, establishes persistence, and retrieves payload locations from an Ethereum smart contract. KREMLIN copies extensions into browser profile directories, regenerates integrity HMACs using browser keys, and enables them without user consent, while also operating as an info-stealer and delivering RATs like REMCOS.
read more →

Attacker Hijacks AI Coding Assistant, Spreads Worm

🛡️ Mandiant reports an attacker hijacked an active AI coding-assistant session at an unnamed SaaS provider and used it to install an infostealer via a poisoned PyPI package. The attacker stole GitHub OAuth tokens and deployed the self-spreading Shai-Hulud worm across about 100 internal repositories, exfiltrating secrets and source code. Mandiant recommends verifying AI-recommended dependencies with checksums and allowlists, restricting extension access to secrets, and routing dependencies through controlled internal repositories to protect AI-assisted development.
read more →

Atomic macOS AMOS stealer activity snapshot

🔎 This Unit 42 analysis documents an AMOS stealer infection observed in a lab on Aug. 5, 2026, providing a snapshot of indicators seen at that time. The report outlines the infection chain beginning with a malicious webpage instructing copy/paste into Terminal, the Zsh scripts and Mach-O binaries used, and the persistence mechanisms under user Library directories. It also details collected artifacts, post‑infection HTTP POST traffic to C2 servers, and the frequent changes in indicators that characterize AMOS as an actively evolving threat.
read more →

Gigabud Uses Work Profiles to Clone Banking Apps

🔒 Group-IB researchers revealed that the Gigabud Android banking trojan has been paired with a weaponized fork of the cloning app Shelter called Vwork, enabling attackers to clone banking apps into isolated Android work profiles. This separation hides malicious activity from signature-based detection in the personal profile and allows fraudsters to perform transactions that appear to originate from clean devices. The campaign was observed primarily in Indonesia but targets users across 11 countries and exploits accessibility and overlay permissions to capture credentials and one-time codes.
read more →

Compiled V8 JavaScript Malware Evades Defenses

🔒 Check Point Research analyzed JSCeal, a sophisticated compiled V8 JavaScript malware used to harvest credentials, surveil victims, and intercept traffic. Operators deliver JSCeal via malvertising and fake trading sites, using Node.js runtimes and obfuscated payloads assembled in memory. The malware targets many Chromium-based browsers to extract cookies, passwords, OAuth tokens, and can replay sessions to access Google accounts. JSCeal also sets up local proxies, installs certificates, and applies service-specific request and response modifications to target crypto platforms and trading services.
read more →

Shai‑Hulud Infostealer Expands Credential Reach

🔍 GitGuardian researchers observed a Shai‑Hulud infostealer worm variant in August that now scans 469 locations for credentials across developer environments, CI/CD tooling, cloud configs, and AI tool settings. Earlier variants checked 189 paths, indicating attackers increasingly hunt for existing reusable authority rather than breaking trust relationships. Defenders are urged to prioritize removing long‑lived publishing tokens, adopt short‑lived identity‑backed publishing, and treat secrets detection as credential risk management.
read more →

Anthropic warns infostealers hijack Claude sessions

🛡️ Anthropic says threat actors are using common infostealer malware to capture active Claude login sessions from infected PCs, then access accounts and consume usage. The company is signing affected users out, removing saved payment methods, and refunding unauthorized charges while its investigation continues. Anthropic identified families such as Vidar, LummaC2, StealC, RedLine and others on Windows, and Atomic Stealer variants on some Macs.
read more →

Weekly ThreatsDay: Botnets, Stealers, and RATs

🔍 This week’s ThreatsDay roundup highlights diverse active campaigns and new tooling, from a 296,000‑device IoT botnet to live operator phishing frameworks and AI‑assisted botnet orchestration. Researchers observed trojanized Electron apps, new stealers and RATs, a Rust backdoor tied to ransomware, and a loader using blockchain for C2. Also covered: a social‑engineering incident at ReliaQuest, an Android fraud bot for rent, and an unpatched disk‑encryption bypass in HP ThinPro.
read more →

Weedhack malware spread via fake Minecraft clients

🛡️ McAfee Labs found ongoing campaigns distributing the Weedhack malware by impersonating popular Minecraft clients and hosting convincing lookalike sites. The attacks use SEO poisoning, Discord and file-hosting links to redirect victims and deploy multi-stage JAR payloads that collect system data and disable security protections. Threat actors even used an AI site builder to create believable malicious domains that outrank legitimate sources.
read more →

Malicious Firefox Add‑Ons Target Crypto Wallets

🔒 Security researchers at Socket uncovered a campaign of linked Firefox add‑ons designed to steal cryptocurrency wallet seed phrases and browser credentials. Dubbed the "Offside Wallet Theft Factory," the operation has been active since at least March 2026 and uses minimal‑permission extensions that switch behavior via a Supabase backend. Some extensions pose as wallets, VPNs, or utilities while others impersonate sports score tools, and attackers remotely toggle malicious pages to harvest recovery phrases and passwords. Out of 77 linked add‑ons, 40 were confirmed to steal data, illustrating how shared code and infrastructure enable rapid weaponization.
read more →