home.social

#informationstealer — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #informationstealer, aggregated by home.social.

fetched live
  1. Lunex Stealer Exploits AMD Driver to Evade Security, Steal Browser Credentials

    Meet Lunex Stealer, a sneaky malware that's rapidly spreading across 13 countries, targeting Ukrainian-speaking users with a powerful information-stealing campaign that can swipe browser credentials and more. Its operators have set up 28 unique control panels, making it a growing threat that's hard to ignore.

    osintsights.com/lunex-stealer-

    #LunexStealer #Malwareasaservice #InformationStealer #BrowserCredentials #AmdDriver

  2. AMOS Stealer Evolves with Frequent Changes

    Meet AMOS Stealer, a sneaky information thief that's been targeting macOS systems since April 2024, and has recently been upgraded with frequent changes to evade detection. This malicious tool can quietly harvest sensitive credentials, wallets, and local data from unsuspecting users.

    osintsights.com/amos-stealer-e

    #AmosStealer #Macos #InformationStealer #Malware #EmergingThreats

  3. Microsoft Uncovers 30+ Domains Linked to MacSync Stealer Infrastructure

    Microsoft's investigation has uncovered a sneaky operation: over 30 domains are secretly linked to MacSync Stealer, a notorious macOS information stealer, and are actively siphoning off sensitive data. The company confirmed that data exfiltration is happening in real-time, not just sending out distress signals.

    osintsights.com/microsoft-unco

    #MacsyncStealer #InformationStealer #MacosMalware #EmergingThreats #DataExfiltration

  4. AmnesiaStealer Malware Hijacks macOS Browser Sessions with Remote Control

    This sneaky malware takes remote control of your macOS browser sessions, allowing hackers to live-stream your screen and even drive your cursor - all without you knowing. They can basically take the reins, controlling your keyboard, mouse, and navigation.

    osintsights.com/amnesiastealer

    #Amnesiastealer #MacosMalware #BrowserSessionHijacking #RemoteControl #InformationStealer

  5. Malicious VS Code Extensions Target Crypto Wallets, API Keys

    Beware: malicious VS Code extensions are targeting crypto wallets and API keys, putting cryptocurrency holders and developers at risk of having their sensitive information stolen. These sneaky extensions, including helper-beeps.solidity-pro and web3devtoolsx.solidity-pro, start off harmless but soon morph into…

    osintsights.com/malicious-vs-c

    #MaliciousVsCodeExtensions #Cryptocurrency #ApiKeyTheft #CredentialTheft #InformationStealer

  6. Windows Stealer Malware Targets 300+ Apps with AI-Powered Profiler

    Meet Dolphin X, a sneaky Windows malware that's taking the cybercrime world by storm with its AI-powered profiler and unparalleled ability to infiltrate over 300 apps, swiping sensitive info like browser passwords, crypto wallets, and cloud tokens. This info-stealer is being sold on the dark web as a potent tool for…

    osintsights.com/windows-steale

    #WindowsStealerMalware #AipoweredProfiler #RemoteAccessTrojan #Rat #Informationstealer

  7. ClickLock Malware Forces macOS Users to Reveal Login Passwords

    Beware: a sneaky new malware called ClickLock has already compromised over 100 macOS systems in 33 countries, tricking users into revealing their login passwords. This stealthy threat has been hiding in plain sight since May, leaving a trail of vulnerable systems in its wake.

    osintsights.com/clicklock-malw

    #Macos #ClicklockMalware #InformationStealer #EmergingThreats #Groupib

  8. macOS Malware Exploits User Trust to Steal Sensitive Data

    Beware of a sneaky new macOS malware that tricks you into stealing your own sensitive data - all it needs is for you to paste a single command into Terminal. Dubbed ClickLock Stealer, this clever con artist has already duped at least 100 victims across 33 countries.

    osintsights.com/macos-malware-

    #MacosMalware #InformationStealer #SocialEngineering #CredentialTheft #EmergingThreats

  9. Microsoft Probes Miasma Campaign as GitHub Repos Remain Offline

    Microsoft swiftly took action to safeguard its customers and the broader ecosystem by temporarily removing some GitHub repositories while investigating a software supply chain intrusion. The company has since restored some, but others remain offline as the probe continues.

    osintsights.com/microsoft-prob

    #SoftwareSupplyChain #Github #Microsoft #EmergingThreats #InformationStealer

  10. PowerShell Stealer Targets Devs via Fake Claude Code Pages

    Developers beware: a sneaky PowerShell Stealer is targeting you through fake Claude Code pages, putting your organization's most sensitive assets at risk. Clicking on innocent-looking sponsored search results could be the first step in a devastating cyberattack.

    osintsights.com/powershell-ste

    #PowershellStealer #FakeClaudeCode #InformationStealer #SupplyChain #DeveloperTools

  11. Cybercriminals Abusing Stack Overflow to Distribute Malware

    Date: May 30, 2024

    CVE: Not specified

    Vulnerability Type: Social Engineering, Malware Distribution

    CWE: [[CWE-494]], [[CWE-434]], [[CWE-22]]

    Sources: BleepingComputer

    Synopsis

    Cybercriminals are exploiting Stack Overflow to distribute malware by posing as helpful users and promoting malicious packages as solutions to programming queries.

    Issue Summary

    Cybercriminals are posing as users on Stack Overflow to answer questions with solutions that involve installing a malicious PyPi package named 'pytoileur'. This package, part of the "Cool package" campaign, targets Windows users by installing information-stealing malware.

    Technical Key Findings

    The malicious package 'pytoileur' includes a setup script that contains an obfuscated Base64 encoded command. This command, when decoded, downloads and executes a malware executable disguised as 'runtime.exe'. This malware is designed to steal sensitive information like cookies, passwords, browser history, and other data from web browsers.

    Vulnerable Products

    • Windows operating systems targeted via the PyPi package 'pytoileur'.

    Impact Assessment

    The malware can steal a wide range of personal and sensitive data, including login credentials, financial information, and personal documents. This data can be sold on dark web markets or used for further cyberattacks.

    Patches or Workaround

    Developers should always verify the authenticity of packages before installation and inspect the code for any obfuscated or unusual commands. No specific patches are provided, but vigilance in package verification is crucial.

    Tags

    #Malware #PyPi #Windows #StackOverflow #InformationStealer #Cybersecurity #SocialEngineering #SoftwareDevelopment #PythonPackages

  12. TA547 Shifts Tactics: Leveraging Rhadamanthys Stealer in German-Specific Campaigns

    Date: April 10, 2024

    CVE: Not applicable

    Vulnerability Type: Information Stealer

    CWE: N/A

    Sources: Proofpoint

    Issue Summary

    TA547, a financially motivated cybercriminal group, recently initiated an email campaign targeting German organizations, deploying the Rhadamanthys malware. This marks TA547's first recorded use of [[Rhadamanthys stealer]], an advanced information stealer previously utilized by multiple threat actors. The campaign featured emails impersonating the German retail giant Metro, with malicious attachments designed to execute Rhadamanthys without writing to disk, thereby evading typical file-based detection methods.

    Technical Key Findings

    The attack chain involves emails with a password-protected ZIP file attachment containing an LNK file. Execution of the LNK file triggers a PowerShell script that decodes and runs the [[Rhadamanthys stealer]] directly in memory. Notably, the PowerShell script exhibited signs of being generated by a Large Language Model (LLM), indicative of TA547's potential use of advanced AI tools for crafting malware delivery mechanisms.

    Vulnerable products

    • Windows platforms targeted via malicious email attachments

    Impact assessment

    [[Rhadamanthys stealer]] is designed to steal sensitive information, including credentials and financial data. Successful deployment within organizations can lead to significant data breaches, financial loss, and reputational damage.

    Patches or workaround

    While the report does not specify patches, organizations are advised to enhance email filtering, educate employees on phishing, and deploy behavior-based detection mechanisms to mitigate threats posed by memory-resident malware and sophisticated delivery scripts.

    Tags

    #TA547 #Rhadamanthys #InformationStealer #Germany #Cybercrime #MalwareCampaign #PowerShell #AI_Malware

Share
Share on Mastodon

Enter the server where you have an account.