< ciso
brief />
Tag Banner

All news with #infostealer tag

403 articles · page 2 of 21

ClickFix macOS campaign and AMOS infostealer

🛡️ This post explains a macOS-focused variant of the ClickFix social-engineering attack that coerces users into pasting malicious commands into Terminal. The script downloads a hidden DMG, mounts it silently, and launches an installer that deploys the AMOS (Atomic macOS Stealer) malware. Once installed, the stealer harvests browser data, crypto wallets, desktop app credentials, Safari and Keychain data, and uploads it to attackers’ servers.
read more →

Malvertising group builds malware inside victim browsers

🛡️ SourTrade, an active malvertising operation since 2024, is concealing its malware assembly inside victim browsers to evade detection. Researchers at Confiant found the campaign impersonates trading and crypto platforms to lure victims with tips and giveaways. Rather than delivering a complete binary, SourTrade sends assembly instructions and clean components that the browser combines in memory to form the final infostealer payload. This in-memory build avoids network fingerprinting and appears as legitimate downloads to security tools.
read more →

Dolphin X infostealer uses AI to prioritize victims

🔍 A new Windows infostealer and RAT named Dolphin X uses an AI-powered profiling system to help operators rank infected machines and identify high-value victims. Advertised on cybercrime forums, it targets over 300 applications to steal credentials, wallets, SSH keys, cloud tokens and DevOps secrets. Varonis Threat Labs analyzed the operator panel and found a scoring system that summarizes daily rankings to streamline attacker triage. Researchers advise defenders to keep long-lived credentials off disk and focus detection on behavior rather than file signatures.
read more →

Exposed server reveals AI-assisted phishing toolkit

🧩 Rapid7 found an exposed delivery server containing 1,048 files: lure templates, tests, droppers, builder notes, and two campaign chains. One campaign targeted Windows users in Mexico via a fake government ID lookup and delivered an infostealer through a WebDAV-hosted exploit. The artifacts included README notes, test matrices, and logs that indicate the operator used generative AI (an open-source coding agent) to create, test, and document phishing delivery at scale. The kit heavily probed a WebDAV working-directory hijack (CVE-2025-33053) and contained tests for other file-handling flaws, while active delivery logs showed thousands of launch events concentrated in Mexico.
read more →

Microsoft warns of surge in ACR Stealer attacks

🛡️ Microsoft reports a marked increase in attacks leveraging ACR Stealer, an info-stealing MaaS that exfiltrates browser passwords, tokens, and sensitive documents from enterprise environments. Between late April and mid‑June, threat actors used social engineering (ClickFix), WebDAV servers, and mshta.exe to deliver obfuscated PowerShell loaders, Python-based installers, and in-memory payloads. The actor abuses GUID-based WebDAV paths, steganographic JPEGs, and public blockchains as dead-drop resolvers to mask activity and maintain C2 communications. Microsoft recommends filters, application control, and limiting access to unnecessary web resources to reduce exposure.
read more →

ACR Stealer campaigns use ClickFix lures and fileless tradecraft

🔍 Microsoft Defender Experts observed heightened ACR Stealer activity from late April to mid-June 2026, using ClickFix social engineering to lure users into running commands that ultimately harvest browser credentials, tokens, and sensitive documents. Two prevalent campaigns were detailed: one using WebDAV-delivered DLLs, staged PowerShell, Python loaders, and optional blockchain-backed dead-drop C2 resolution; the other using fileless MSHTA, obfuscated PowerShell, and steganography-assisted in-memory execution. Both aim to exfiltrate credentials and enterprise data, and Microsoft recommends monitoring for ClickFix lures, suspicious WebDAV/MSHTA activity, obfuscated PowerShell, and attempts to access browser credential stores while leveraging Defender capabilities to detect and respond.
read more →

OkoBot framework deploys 20+ payloads to steal crypto

🛡️ A new modular malware framework named OkoBot delivers over 20 payloads to steal cryptocurrency seed phrases, credentials, and other sensitive data. The campaign uses ClickFix lures and malicious GitHub repositories, sometimes trojanizing legitimate tools, and evolved from the earlier TookPS activity. Kaspersky found the campaign active since January and primarily targeting victims in Brazil, Vietnam, Canada, Mexico, and Turkey. Notable modules include browser injectors, SeedHunter for wallet recovery prompts, keyloggers, and spyware that records wallet and password manager windows.
read more →

ClickLock macOS stealer leverages ClickFix social lure

🛡️ Group-IB researchers describe a new macOS stealer called ClickLock that combines a ClickFix "paste-a-command" lure with a coercion routine that disables the desktop until a password is surrendered. The modular campaign downloaded four components from compromised WordPress sites to steal Keychain and browser credentials, exfiltrate wallet data, and install a GSocket backdoor. Operators forced compliance by killing system processes in loops, suppressing warnings and relaunching credential prompts; exfiltration used Telegram bots and modules self-deleted, leaving a stealthy backdoor.
read more →

The TTF Trap: Lua Loader Campaign Analysis

🔍 Since late March 2026, FortiGuard Labs documented a global phishing campaign that uses heavily obfuscated JScript droppers and AutoIt/Lua-based loaders disguised as .ttf files to deploy RATs and infostealers. Attackers impersonate reputable organizations to deliver malicious archives that stage multi-layered loaders with low detection rates. The campaign ultimately deploys payloads like Agent Tesla, Remcos, XWorm, and Snake-derived keyloggers, enabling remote control and data theft.
read more →

TELEPUZ modular malware spreads via ClickFix attacks

🛡️ Elastic Security Labs disclosed a new lightweight, modular malware named TELEPUZ that has been propagated through ClickFix (pastejacking) lures since late April 2026. The campaign delivers a Go-based Vidar stealer variant which then fetches a C-based TELEPUZ stager and main DLL, with artifacts hosted on a domain linked to the campaign. TELEPUZ includes extensive obfuscation, anti-VM and geofencing checks, AMSI/ETW unhooking, privilege escalation, service persistence, and WebSocket-based C2 with fallback retrieval via Telegram, Steam, DNS and a Polygon smart contract.
read more →

macOS infostealer poses as Apple crash reporter

🛡️ A new macOS infostealer named CrashStealer impersonates Apple's crash-reporting component to trick users into installing a password-stealing payload. Delivered via a signed, notarized disk image called "Werkbit Setup," the dropper bypasses Gatekeeper and fetches a downloader that installs the C++-based stealer. Once active, it prompts for system credentials and exfiltrates browser-stored logins, crypto wallet access and keychain data, using client-side encryption and anti-analysis techniques.
read more →

Jscrambler npm package compromised with infostealer

🛡️ Jscrambler disclosed that a threat actor published malicious npm releases (8.14, 8.16, 8.17, 8.20) containing an info-stealer executed via the preinstall hook. The tampered package was live for two hours, downloaded 1,479 times, and affected four dependent packages that were deprecated and replaced. Jscrambler revoked compromised publishing credentials and urged users to rotate secrets and update to the safe release.
read more →

CrashStealer macOS info stealer uses signed dropper

🛡️ Jamf Threat Labs discovered a new native C++ macOS information stealer named CrashStealer that harvests credentials, browser data, cryptocurrency wallet extensions, password manager entries, and keychain material. The campaign uses a signed and Apple-notarized disk image dropper served from a gated site and persists via LaunchAgent after re-signing itself. Collected files are AES-GCM encrypted before exfiltration to an attacker-controlled server, and the malware employs multiple analysis-resistance techniques.
read more →

ModHeader removed after hidden browsing-history collector

🛡️ Google and Microsoft removed the popular ModHeader extension after researchers found a dormant browsing-history collector embedded in the official store builds. The collector, confirmed by Stripe OLT to be in the genuine Chrome package, stored encrypted domain lists and device fingerprints locally and was designed to upload them to api.stanfordstudies[.]com on a schedule if an internal allow-list were populated. While the allow-list shipped empty and no evidence shows data was exfiltrated, the extension still pinged extensions-hub[.]com and logged request metadata locally. Users are advised to uninstall ModHeader, rotate exposed secrets, and defenders should block the implicated domains and hunt for related indicators.
read more →

Injective SDK npm package used to steal wallet keys

🔒 Security researchers discovered that the @injectivelabs/sdk-ts npm package (v1.20.21) was published with malicious code to capture cryptocurrency wallet private keys and mnemonic seed phrases. The compromise stemmed from a hijacked GitHub contributor account with suspicious commits appearing on June 8; the legitimate owner quickly reverted changes and released a clean 1.20.23. The malware activated when wallet-generation or import functions were called and exfiltrated secrets via HTTP POST to a public Injective Labs endpoint, and the tainted package had hundreds of dependent packages and thousands of downloads.
read more →

Fake Paysafe, Skrill SDKs on npm and PyPI steal creds

🔒 Malicious packages impersonating Paysafe, Skrill, and Neteller SDKs were published to npm and PyPI, delivering credential-stealing malware to developers and applications. Socket discovered 17 packages that expose expected APIs but return fake success responses while searching for and exfiltrating secrets such as API keys, tokens, and AWS credentials. Developers who installed these packages are urged to rotate secrets, inspect dependency trees and CI logs, and block the malicious package names at registry proxies.
read more →

North Korean campaign publishes malicious packages

🛡️ Researchers observed North Korea–linked actors behind the Contagious Interview campaign publish 108 unique malicious packages and extensions across npm, Packagist, Go, and Chrome under an operation dubbed PolinRider. The releases include obfuscated JavaScript loaders that append code to common project config files and leverage VS Code task auto-run behavior to execute payloads. Attackers appear to acquire or retain registry and maintainer access via repository compromises, domain takeovers, or malicious dependencies. The campaign has been active since at least 2023 and continues to deliver RATs and stealers through multi-stage blockchain-backed payload delivery.
read more →

PamStealer macOS stealer uses fake Maccy sites

🛡️ Cybersecurity researchers have identified PamStealer, a macOS information stealer distributed as a compiled AppleScript masquerading as the open-source clipboard manager Maccy. The dropper fetches a Rust-based Mach-O stealer that harvests browsers, wallet extensions, iCloud Keychain, and clipboard data, then exfiltrates it to attacker infrastructure. The malware also coerces victims into entering their system password and validates it via PAM before capturing it.
read more →

Silent Swap clipper exploits browser extensions

🛡️ McAfee Labs uncovered an active campaign, dubbed Silent Swap, that deploys malicious Chromium extensions masquerading as a 'Google Notes' utility to intercept and replace cryptocurrency wallet addresses copied to the clipboard. The installers, observed in .NET and Golang variants, inject the extension into Chromium-based browsers by modifying protected preferences and recalculating security hashes to bypass store installation. The threat uses an EtherHiding technique to resolve C2 domains via the blockchain and performs dynamic, server-side wallet mappings to redirect funds to attacker-controlled addresses. Telemetry shows global infections, with higher concentration in India.
read more →

ClickFix Emerges as Dominant Malware Delivery Method

🔒 Analysis by ReliaQuest shows the ClickFix social engineering technique dominated malware delivery from March to May 2026. ClickFix tricks users into pasting attacker-supplied commands into trusted dialogs like Run, Terminal, or Script Editor, allowing payloads such as infostealers to execute while evading many defenses. The method has been used to deliver Windows malware and, notably, to deploy AMOS/Atomic Stealer to macOS via Script Editor. ReliaQuest urges equal monitoring for macOS and recommends user training and administrative restrictions to mitigate ClickFix risks.
read more →