Skip to main content

Threats Tagged 'browser data theft'

View all threats tagged with 'browser data theft'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: browser data theft

Threats Tagged 'browser data theft'

Click on any threat for detailed analysis and mitigation recommendations

Cybercriminals are exploiting the hype around Grand Theft Auto VI by creating fake websites that impersonate official Rockstar Games promotional material. These sites offer a GTA 6 demo download which is actually a Vidar infostealer malware. The malware steals sensitive browser data including passwords, cookies, session tokens, autofill data, and FTP credentials from multiple browsers. It uses legitimate browser binaries in headless mode to bypass protections and steal data more effectively. Stolen session tokens can bypass two-factor authentication, allowing persistent unauthorized access even after password changes. This campaign leverages recent GTA 6 leaks to lure victims.

Join the discussion

PamStealer is a two-stage macOS infostealer distributed as a compiled AppleScript impersonating Maccy, a legitimate clipboard manager, hosted on a fake domain. The first stage uses JavaScript for Automation with Objective-C APIs to download payloads while avoiding shell commands. The second stage is a Rust-based Mach-O binary that validates stolen credentials through PAM before harvesting, reads browser databases directly using bundled SQLite, captures clipboard contents repeatedly via pbpaste, and exfiltrates encrypted data using ChaCha20-Poly1305. It establishes persistence through both modern and legacy login item APIs, masquerades as Finder or System Settings, and tricks victims into granting Full Disk Access through counterfeit alerts. The stealer contacts Ethereum RPC endpoints and employs region-based exclusions targeting Apple silicon systems while avoiding Commonwealth of Independent States countries.

Join the discussion

A sophisticated Rust-based macOS implant named macOS.Gaslight has been discovered, featuring a novel 3.5 KB prompt-injection payload containing 38 fabricated system messages designed to disrupt LLM-assisted malware analysis. The backdoor communicates via Telegram Bot API with AES-GCM encrypted payloads over certificate-pinned TLS and includes self-redaction capabilities to hide its bot token from logs. It provides operators with an interactive shell, system information collection, and credential stealing capabilities through a bundled Python script that targets browser data, keychains, and command histories. The implant uses runtime-fetched CPython interpreters and establishes persistence through a LaunchAgent masquerading as an Apple system service. This threat is assessed with high confidence to be aligned with DPRK activity and represents a significant evolution in adversarial techniques targeting security analysts rather than sandbox environments.

Join the discussion

NWHStealer is a Windows infostealer malware actively distributed through multiple platforms including fake Proton VPN websites, code and file hosting services, and YouTube links. It steals browser data, saved passwords, and information from over 25 cryptocurrency wallets. The malware uses two main infection methods: malicious ZIP files with self-injection loaders hosted on free web hosting providers, and fake websites employing DLL hijacking to inject code into the RegAsm process. It exfiltrates stolen data encrypted with AES-CBC to attacker-controlled servers and maintains persistence via scheduled tasks and UAC bypass techniques. There is no known official patch or vendor advisory for this threat. Indicators include specific malicious domains and file hashes.

Join the discussion

A deceptive website impersonating CleanMyMac tricks users into installing SHub Stealer, a sophisticated macOS malware. The malware steals sensitive data, including passwords, browser data, cryptocurrency wallets, and Telegram sessions. It can also modify wallet apps to steal recovery phrases. The attack begins with users pasting a command into Terminal, which downloads and executes a malicious script. The malware performs extensive data collection from various browsers and wallet applications, and installs persistent backdoors in certain crypto wallet apps. SHub Stealer is part of a growing family of AppleScript-based macOS infostealers, demonstrating increasing sophistication in targeting Mac users.

Join the discussion

Arkanix Stealer, a newly discovered malware operating under a Malware-as-a-Service model, targets a wide range of user data including cryptocurrencies, gaming, and online banking information. The stealer, available in both Python and C++ versions, offers configurable features and employs various techniques to evade detection. It can extract data from multiple browsers, VPNs, and gaming platforms, as well as capture screenshots and RDP connection details. The malware authors promoted their product through a Discord server and implemented a referral program to attract customers. The campaign appears to have been short-lived, with infrastructure taken down around December 2025.

Join the discussion

Marco Stealer, discovered in June 2025, is an information stealer targeting browser data, cryptocurrency wallets, and sensitive files. It employs anti-analysis techniques, string encryption, and terminates security tools. The malware collects system information, exfiltrates browser data using embedded files, and extracts cryptocurrency wallet data from browser extensions. It also targets popular services and cloud storage. Marco Stealer uses AES-256 encryption for C2 communication over HTTP. Despite recent law enforcement actions against similar threats, information stealers continue to pose significant risks to corporate environments.

Join the discussion

The VVS Discord Stealer is a Python-based malware designed to exfiltrate sensitive Discord user data including credentials and tokens. It uses Pyarmor with BCC mode and AES-128-CTR encryption to heavily obfuscate its code, evading detection by static and dynamic analysis tools. The malware decrypts encrypted Discord tokens, queries Discord APIs for user information, injects malicious JavaScript into the Discord client to intercept active sessions, and extracts data from multiple web browsers. It achieves persistence by configuring itself to run at system startup and deceives victims by displaying a fake error message. While no known exploits or CVEs are reported, its capabilities pose a medium severity threat. The stealer primarily targets Windows environments where Discord and browsers are installed and relies on user interaction, likely via social engineering. European organizations with significant Discord usage, especially in technology, gaming, media, and education sectors, face risks of credential theft, unauthorized access, data leakage, and operational disruption. Detection requires behavioral and heuristic analysis due to strong obfuscation techniques.

Join the discussion

A sophisticated infostealer dubbed NordDragonScan has been discovered, targeting Windows systems through weaponized HTA scripts. The malware is distributed via shortened links leading to RAR archives containing malicious LNK shortcuts. Once installed, NordDragonScan performs extensive reconnaissance, collecting system information, network details, browser data, and sensitive documents. It utilizes custom obfuscation techniques and establishes persistence through registry modifications. The stolen data is exfiltrated to a command-and-control server using TLS encryption. The attack employs various decoy documents to evade detection and maximize infection opportunities. NordDragonScan's capabilities include screenshot capture, Chrome and Firefox profile harvesting, and local network scanning.

Join the discussion

In May 2025, Cisco Talos identified a Python-based remote access trojan (RAT) called 'PylangGhost', used by a North Korean-aligned threat actor. PylangGhost shares similarities with the previously documented GolangGhost RAT. The threat actor, Famous Chollima, has been targeting employees with experience in cryptocurrency and blockchain technologies through fake job interview sites. The attacks primarily affect users in India. The malware is deployed through a two-stage process involving fake skill-testing pages and malicious command execution. PylangGhost consists of six Python modules and offers functionalities similar to its Golang counterpart, including system information collection, file manipulation, and browser data theft from over 80 extensions.

Join the discussion

Showing 1 to 10 of 11 results

Filters:Tag: browser data theft
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses