home.social

#stealc — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #stealc, aggregated by home.social.

fetched live
  1. Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

    Between July 21-22, 2026, 29 organizations were compromised through a sophisticated malvertising campaign exploiting Claude AI's legitimate domain. Victims searching for Claude Desktop via Bing encountered sponsored advertisements leading to a malicious Claude Artifact hosted on the authentic Claude.ai domain. This artifact redirected users to attacker-controlled infrastructure distributing a fake ClaudeDesktop.exe file containing SectopRAT. The malware employed advanced anti-analysis techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption. Command-and-control infrastructure utilized EtherHiding, storing C2 addresses in Ethereum blockchain transactions for resilience against takedowns. The remote access trojan exfiltrated credit card data, credentials, browser information, and personal files. Analysis revealed connections to previous campaigns dating to December 2025, with infrastructure linked to Operation Endgame seizures and StealC distrib...

    Pulse ID: 6a616004250472ee87e19829
    Pulse Link: otx.alienvault.com/pulse/6a616
    Pulse Author: AlienVault
    Created: 2026-07-23 00:27:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #CreditCard #CyberSecurity #EtherHiding #InfoSec #Mac #Malvertising #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Stealc #Trojan #Troll #bot #AlienVault

  2. Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

    Between July 21-22, 2026, 29 organizations were compromised through a sophisticated malvertising campaign exploiting Claude AI's legitimate domain. Victims searching for Claude Desktop via Bing encountered sponsored advertisements leading to a malicious Claude Artifact hosted on the authentic Claude.ai domain. This artifact redirected users to attacker-controlled infrastructure distributing a fake ClaudeDesktop.exe file containing SectopRAT. The malware employed advanced anti-analysis techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption. Command-and-control infrastructure utilized EtherHiding, storing C2 addresses in Ethereum blockchain transactions for resilience against takedowns. The remote access trojan exfiltrated credit card data, credentials, browser information, and personal files. Analysis revealed connections to previous campaigns dating to December 2025, with infrastructure linked to Operation Endgame seizures and StealC distrib...

    Pulse ID: 6a616004250472ee87e19829
    Pulse Link: otx.alienvault.com/pulse/6a616
    Pulse Author: AlienVault
    Created: 2026-07-23 00:27:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #CreditCard #CyberSecurity #EtherHiding #InfoSec #Mac #Malvertising #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Stealc #Trojan #Troll #bot #AlienVault

  3. 📣🚨 #OperationEndgame disrupts StealC malware infrastructure, seizing millions of stolen credentials and targeting servers used in global cybercrime campaigns.

    Listen or Read: hackread.com/operation-endgame

    #CyberSecurity #Malware #InfoStealer #CyberCrime #StealC

  4. 📣🚨 #OperationEndgame disrupts StealC malware infrastructure, seizing millions of stolen credentials and targeting servers used in global cybercrime campaigns.

    Listen or Read: hackread.com/operation-endgame

    #CyberSecurity #Malware #InfoStealer #CyberCrime #StealC

  5. Lees tip -> Politie haalt malware StealC en Amadey offline in Operatie Endgame | Bij een internationale actie tegen infostealers zijn criminele servers offline gehaald. Politie vond ruim 24 miljoen logingegevens van zeker 384.000 besmette systemen. | #ransomware #politie #infostealers #Europol #cybercrime #StealC #malware #Eurojust #OperatieEndgame #Amadey |

    hbpmedia.nl/politie-haalt-malw

  6. DocSend.exe signed "Taiyuan Yuqianhan Network Technology Co., Ltd."; Certificate reported
    b409adb785f58f1de1cdf12e5c7c51a2

    C2: 185.174.133.12
    https://tria[.]ge/260211-2qa1ascw9d/behavioral1
    #StealC

    h/t @malwrhunterteam

  7. Badacze zhakowali panel administracyjny infostealera StealC. Wszystko przez XSS i błędy w konfiguracji

    Malware StealC jest dobrze znany zarówno w środowisku cyberprzestępców jak i badaczy bezpieczeństwa. Popularność zyskał przede wszystkim za sprawą niskiego progu wejścia dla atakujących oraz wysoką skutecznością działania. Jest oferowany w modelu Malware-as-a-Service (MaaS). Charakteryzuje się masowym wykradaniem ciasteczek sesyjnych (pliki cookie), kradzieżą danych z portfeli kryptowalutowych oraz wsparciem dla...

    #WBiegu #Clickfix #Infostealer #Malware #Stealc #XSS #Youtube

    sekurak.pl/badacze-zhakowali-p

  8. Badacze zhakowali panel administracyjny infostealera StealC. Wszystko przez XSS i błędy w konfiguracji

    Malware StealC jest dobrze znany zarówno w środowisku cyberprzestępców jak i badaczy bezpieczeństwa. Popularność zyskał przede wszystkim za sprawą niskiego progu wejścia dla atakujących oraz wysoką skutecznością działania. Jest oferowany w modelu Malware-as-a-Service (MaaS). Charakteryzuje się masowym wykradaniem ciasteczek sesyjnych (pliki cookie), kradzieżą danych z portfeli kryptowalutowych oraz wsparciem dla...

    #WBiegu #Clickfix #Infostealer #Malware #Stealc #XSS #Youtube

    sekurak.pl/badacze-zhakowali-p

  9. The other day I was thinking, when will infostealers start collecting information from "AI" browsers.

    Today noticed that StealC has posted an update, where they added a feature of collecting Sigma AI Browser data.

    ''Sigma AI Browser is an AI‑first agentic browser that combines an AI agent, deep research, and AI tools to help you navigate, create, and'' sloooop

    Anyways, left to find some time and energy to look for some stealc logs and see if it syphons some more juicy data from "ai" browsers.

    #StealC #infostealer #AIbrowser #threatintel

  10. The other day I was thinking, when will infostealers start collecting information from "AI" browsers.

    Today noticed that StealC has posted an update, where they added a feature of collecting Sigma AI Browser data.

    ''Sigma AI Browser is an AI‑first agentic browser that combines an AI agent, deep research, and AI tools to help you navigate, create, and'' sloooop

    Anyways, left to find some time and energy to look for some stealc logs and see if it syphons some more juicy data from "ai" browsers.

    #StealC #infostealer #AIbrowser #threatintel

  11. Mentioned Malware Families: Stealc, NightshadeC2

    Aliases for Stealc: win.stealc
    Malpedia link for Stealc: malpedia.caad.fkie.fraunhofer.
    Aliases for NightshadeC2: win.nightshade_c2, CastleRAT
    Malpedia link for NightshadeC2: malpedia.caad.fkie.fraunhofer.

    #Stealc #NightshadeC2

    Aliases provided by Malpedia.

  12. Here's the full infection chain:

    • 198.211.110.107:79 finger connects to finger[.]cloudyape[.]com
    • 172.67.190.68:80 curl tries cloudyape[.]com/uvey.php?holt=2 but server responds with '301 Moved Permanently' and redirects to HTTPS
    • 172.67.190.68:443 dropper download
    • 172.67.190.68:80 curl gets cloudyape[.]com/uvey.php?holt=1 server redirects to HTTPS
    • 172.67.190.68:443 dropper download
    • 170.130.165.201:80 Download of file4.bin (#StealC) with fake GoogeBot user agent
    • 170.130.165.201:80 #StealC v2 C2 / exfiltration
    • 170.130.55.38:80 #CastleLoader traffic
    • 194.76.227.242:9999 #CastleRAT C2 traffic
  13. This #StealC and #CastleRAT infection starts with a #ClickFix attack using finger to download commands from finger[.]cloudyape[.]com