#stealc — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #stealc, aggregated by home.social.
-
#Anthropic warnt Opfer von Infostealern | Security https://www.heise.de/news/Anthropic-warnt-Opfer-von-Infostealern-11436179.html #Infostealer #Vidar #Lumma #StealC #RedLine #Acreed #Windows :windows: #AtomicStealer #macOS #malware #Microsoft #MicrosoftWindows :windows: #Apple :apple_inc: #macOS #ArtificialIntelligence #AI #Datenschutz #privacy #Datenleck #DataLeak
-
Infostealers can steal active Claude sessions, bypass 2FA and drain paid usage. Anthropic is revoking access and refunding unauthorized charges.
#Claude #VidarStealer #LummaC2Stealer #Stealc #RedLineStealer #AcreedStealer #AtomicStealer
https://securityaffairs.com/198166/ai/infostealers-are-hijacking-claude-sessions-and-draining-subscriptions.html -
AgentBaiting – nowa technika ataku zaobserwowana w kampanii FakeGit
Badacze bezpieczeństwa z firmy Island wzięli na warsztat kampanię cyberprzestępczą, znaną pod kryptonimem FakeGit. W ramach prac wykryto około 7600 złośliwych repozytoriów, z czego ponad 800 podszywało się pod rozszerzenia AI lub serwery MCP. Oferowały one zarówno integracje dla użytkowników prywatnych (Gmail, WhatsApp), jak i narzędzia firmowe (Databricks, Jenkins, Docker). ...
#WBiegu #AgentBaiting #Ai #Fakegit #Infostealer #Stealc
https://sekurak.pl/agentbaiting-nowa-technika-ataku-zaobserwowana-w-kampanii-fakegit/
-
StealC and Amadey: Breaking down infostealers and the cybercrime services thatdeliver them - https://www.redpacketsecurity.com/stealc-and-amadey-breaking-down-infostealers-and-the-cybercrime-services-thatdeliver-them/
#threatintel
#infostealers
#StealC
#Amadey
#malware-as-a-service
#cybercrime-economy -
📣🚨 #OperationEndgame disrupts StealC malware infrastructure, seizing millions of stolen credentials and targeting servers used in global cybercrime campaigns.
Listen or Read: https://hackread.com/operation-endgame-stealc-amadey-socgholish-malware/
-
Lees tip -> Politie haalt malware StealC en Amadey offline in Operatie Endgame | Bij een internationale actie tegen infostealers zijn criminele servers offline gehaald. Politie vond ruim 24 miljoen logingegevens van zeker 384.000 besmette systemen. | #ransomware #politie #infostealers #Europol #cybercrime #StealC #malware #Eurojust #OperatieEndgame #Amadey |
https://hbpmedia.nl/politie-haalt-malware-stealc-en-amadey-offline-in-operatie-endgame/
-
StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them
#Stealc #Amadey
https://www.microsoft.com/en-us/security/blog/2026/06/24/stealc-and-amadey-breaking-down-infostealers-and-the-cybercrime-services-that-deliver-them/ -
https://app.any.run/tasks/9cd9a0f0-bf6f-4a23-9bf0-4d804f816b07
c2: https:// pas. canamrent .com/
-
SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2)
#SmartApeSG #RemcosRAT #Stealc #SecTopRAT
https://isc.sans.edu/diary/32826 -
ISC Diary: #SmartApeSG campaign pushes #Remcos #RAT, #NetSupportRAT, #StealC and #SectopRAT (#ArechC https://isc.sans.edu/diary/32826
-
Middle East Conflict Fuels Opportunistic Cyber Attacks
#LOTUSLITE #Stealc
https://www.zscaler.com/blogs/security-research/middle-east-conflict-fuels-opportunistic-cyber-attacks -
https://winbuzzer.com/2026/02/19/fake-captcha-trick-installs-stealc-on-windows-pcs-xcxwbn/
Fake CAPTCHA Trick Installs StealC on Windows PCs
#Windows #Security #Cybersecurity #StealC #Malware #Cybercrime #Hackers #WindowsSecurity #PowerShell #Scams #DataTheft #ThreatActors #CyberThreats #Cyberattacks #MicrosoftOutlook #Steam #Cryptocurrency
-
DocSend.exe signed "Taiyuan Yuqianhan Network Technology Co., Ltd."; Certificate reported
b409adb785f58f1de1cdf12e5c7c51a2C2: 185.174.133.12
https://tria[.]ge/260211-2qa1ascw9d/behavioral1
#StealCh/t @malwrhunterteam
-
Badacze zhakowali panel administracyjny infostealera StealC. Wszystko przez XSS i błędy w konfiguracji
Malware StealC jest dobrze znany zarówno w środowisku cyberprzestępców jak i badaczy bezpieczeństwa. Popularność zyskał przede wszystkim za sprawą niskiego progu wejścia dla atakujących oraz wysoką skutecznością działania. Jest oferowany w modelu Malware-as-a-Service (MaaS). Charakteryzuje się masowym wykradaniem ciasteczek sesyjnych (pliki cookie), kradzieżą danych z portfeli kryptowalutowych oraz wsparciem dla...
#WBiegu #Clickfix #Infostealer #Malware #Stealc #XSS #Youtube
-
The other day I was thinking, when will infostealers start collecting information from "AI" browsers.
Today noticed that StealC has posted an update, where they added a feature of collecting Sigma AI Browser data.
''Sigma AI Browser is an AI‑first agentic browser that combines an AI agent, deep research, and AI tools to help you navigate, create, and'' sloooop
Anyways, left to find some time and energy to look for some stealc logs and see if it syphons some more juicy data from "ai" browsers.
-
UNO reverse card: stealing cookies from cookie stealers
#Stealc
https://www.cyberark.com/resources/threat-research-blog/uno-reverse-card-stealing-cookies-from-cookie-stealers -
Last week, Microsoft reported that their Digital Crimes Unit (DCU) and international partners disrupted Lumma Stealer by taking down 2,300 domains critical to the malware's operation. Shortly after, Palo Alto's Unit 42 reported about cyber campaigns that previously dropped Lumma Stealer are now distributing StealC infostealer payloads. We analyzed the DNS infrastructure related to the attacks and discovered a large number of malicious registered domain generation algorithm (RDGA) domains. Based on passive DNS, the threat actor that controls the infrastructure configured the domains to a staging environment via a dedicated Panama IP address (self-signed SSL) before deploying them. We identified 144 unique domains in this IP space, and all of them were detected as "suspicious" by our algorithms 1-2 months before they were activated for malicious activity.
Disrupting criminal operations is difficult and they will find ways to resurface. However, this example proves that blocking connections at the DNS level can often protect users against the new versions before they emerge. The infostealer actors made a quick turn, but we were already blocking their path. Our specialty is in DNS analytics, so we use DNS signatures, as opposed to malware signatures, for preemptive security. We love this stuff.
Here are some examples of the RDGA domains:
2323dot2[.]cfd, 2323dot2[.]cyou, 2323dot2[.]my, 232pip1[.]my, 232pip1[.]sbs, 832pip[.]cfd, 832pip[.]cyou, 832pip[.]my, 832pip[.]sbs, b3cloud[.]cfd, b3cloud[.]cyou, b3cloud[.]my, b3cloud[.]sbs, bin48[.]cfd, bin48[.]cyou, bin48[.]my, bin898293[.]cfd, bin898293[.]cyou, bin898293[.]my, bin898293[.]sbs, bit7dl[.]cfd, bit7dl[.]cyou, bit7dl[.]my, bit7dl[.]sbs, bot113cloud[.]cfd, bot113cloud[.]cyou, bot113cloud[.]my
These campaigns share similar TTPs with those that we reported several months ago. The threat actor that we discussed in this post (https://infosec.exchange/@InfobloxThreatIntel/114027715851469775) also distributed Lumma Stealer and used RDGA domains, but incorporated additional components, such as traffic distribution systems (TDS), web trackers, and cloakers.
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #infostealer #lummastealer #stealc #tds #tracker #cloaker #rdga -
2025-04-22 (Tuesday): Always fun to find the fake CAPTCHA pages with the #ClickFix style instructions trying to convince viewers to infect their computers with malware.
Saw #StealC from an infection today.
Indicators available at https://github.com/malware-traffic/indicators/blob/main/2025-04-22-IOCs-for-ClickFix-style-campaign-leading-to-StealC-infection.txt