Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

June 2026 Infostealer Trend Report

0
Medium
Published: 07/15/2026 (07/15/2026, 11:58:14 UTC)
Source: AlienVault OTX General

Description

During June 2026, multiple infostealer families including Remus, ACRStealer, LummaC2, and Vidar were distributed through SEO poisoning techniques, disguised as illegal software such as cracks and keygens. Attacks utilized EXE files (84.5%) and DLL side-loading (15.5%) methods, with distribution primarily through Mediafire, Mega, and cloud storage platforms. Microsoft Corporation was the most frequently impersonated entity. MacOS environments were targeted through ClickFix techniques and malicious Bash scripts, with one variant dynamically obtaining C2 addresses via Polygon smart contracts. Email-based campaigns distributed AgentTesla and DarkCloud through compressed attachments, with both variants exfiltrating data via SMTP. The stolen credentials pose significant risks for dark web trading and secondary attacks.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/15/2026, 22:03:35 UTC

Technical Analysis

This threat report details the distribution and activity of multiple infostealer malware families during June 2026. Attackers used SEO poisoning to lure victims into downloading malicious EXE files (84.5%) and DLL side-loading payloads (15.5%), primarily hosted on Mediafire, Mega, and other cloud platforms. Microsoft Corporation was frequently impersonated to increase credibility. MacOS environments were targeted using ClickFix and malicious Bash scripts, with one variant leveraging Polygon blockchain smart contracts to dynamically retrieve command and control addresses. Email-based campaigns delivered AgentTesla and DarkCloud malware via compressed attachments, with both variants exfiltrating stolen data through SMTP. The compromised credentials are valuable for dark web trading and enable secondary attacks. No known exploits in the wild or vendor patches are applicable as this is malware distribution rather than a software vulnerability.

Potential Impact

Successful infections result in credential theft and data exfiltration, enabling attackers to trade stolen information on dark web markets and conduct secondary attacks. The targeting of both Windows and MacOS platforms broadens the potential victim base. The use of blockchain smart contracts for C2 address retrieval complicates detection and takedown efforts. Impersonation of Microsoft increases the likelihood of victim trust and infection.

Defensive Guidance

This is a malware distribution campaign rather than a software vulnerability; therefore, no patches are available or applicable. Organizations should focus on user awareness to avoid downloading software from untrusted sources, especially cracked or pirated software. Email filtering and attachment scanning can help detect and block AgentTesla and DarkCloud payloads. Monitoring for indicators of compromise such as the provided hashes and domains is recommended. Since no official vendor remediation applies, defensive measures should emphasize prevention and detection of these malware families.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://asec.ahnlab.com/en/94486/"]
Adversary
null
Pulse Id
6a5775d6071af081378a0eb9
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hashd15248555e7a2d9c279d219e6587a74fca9c25720194512a2e4b0757f7a63219
hash02c7d78e6c5816f1df250f995a776aa2
hash03663f2f81da94cd204837e4bde772ff
hash03e99ceede013fe1b50a0e06c1f0a02c
hash042db31ea5443d78aeee714556813a28
hash04d91c168c7617c38199983858cfbb4e
hashc8c80cde1ae90d6a594980e117977437de97ebb1
hashdbe028a59ffe936bce9acb56e9c2db93ef6f84fe
hashac14d191300c2d3aa9f57829b895b7720be1ef3563bace25de731002d52577f7

Domain

ValueDescriptionCopy
domainapdhlhs3.xyz
domainbduwih8.pro
domainjohncon.my

Threat ID: 6a58000568715ace438b184a

Added to database: 07/15/2026, 21:47:49 UTC

Last enriched: 07/15/2026, 22:03:35 UTC

Last updated: 08/15/2026, 04:52:33 UTC

Views: 133

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses