Threats Tagged 'information theft'
View all threats tagged with 'information theft'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'information theft'
Click on any threat for detailed analysis and mitigation recommendations
A sophisticated malware campaign delivering PureLog Stealer has been identified, targeting healthcare, government, hospitality, and education sectors in multiple countries. The attack uses localized copyright violation lures to trick victims into executing a multi-stage infection chain. The malware employs encrypted payloads, remote key retrieval, and fileless execution techniques to evade detection. It utilizes a Python-based loader and dual .NET loaders to run PureLog Stealer entirely in memory. The campaign incorporates AMSI bypass, registry persistence, screenshot capture, and victim fingerprinting for stealth and intelligence gathering. Evidence confirms communication with PureLog-associated infrastructure. MediumMalware Join the discussion | AlienVault OTX General | 03/20/2026, 08:13:38 UTC Added: 03/20/2026, 08:23:29 UTC |
The Stealit malware campaign leverages Node.js Single Executable Application (SEA) technology to distribute malicious payloads as standalone binaries, bypassing the need for a Node.js runtime. Distributed mainly as disguised game and VPN installers via file-sharing sites, the malware employs heavy obfuscation and anti-analysis techniques to evade detection. Once executed, it acts as a Remote Access Trojan (RAT), stealing sensitive information such as login credentials and cryptocurrency wallet data. The campaign demonstrates adaptability by switching between Node.js SEA and Electron frameworks for payload delivery. Although no known exploits are currently active in the wild, the malware’s capability to control victim systems and extract valuable data poses a significant threat. The campaign’s medium severity rating reflects its stealth and information theft focus, with no immediate widespread exploitation reported. European organizations using Node. Join the discussion | AlienVault OTX General | 10/11/2025, 02:50:55 UTC Added: 10/13/2025, 10:24:06 UTC |
This analysis delves into the operations of DeceptiveDevelopment, a North Korea-aligned threat actor, and its connections to North Korean IT worker campaigns. The group targets software developers across major systems, focusing on cryptocurrency and Web3 projects. They use social engineering techniques like fake job offers and the ClickFix method to deliver malware. Their toolset includes multiplatform malware such as BeaverTail, InvisibleFerret, WeaselStore, and TsunamiKit. The group shows links to other North Korean cyber operations through shared malware like Tropidoor and AkdoorTea. The analysis also explores the activities of North Korean IT workers, who use stolen identities and AI-generated content to secure remote jobs, highlighting the interconnected nature of these cyber threats. Join the discussion | AlienVault OTX General | 09/25/2025, 16:29:04 UTC Added: 09/25/2025, 19:13:16 UTC |
A 2D platformer game called BlockBlasters on Steam has been infected with malware disguised as a patch. The malicious update, released on August 30, 2025, contains files that exhibit multiple malicious behaviors, including stealing crypto wallet data and other sensitive information from users' PCs. The infection process involves multiple stages, including a trojan stealer batch file, VBS loaders, and the main payload consisting of a backdoor and the StealC stealer malware. The campaign affects hundreds of players who have installed the game. The malware collects IP and location information, detects installed antivirus products, gathers login credentials, and uploads data to command and control servers. The game has since been removed from Steam, but not before causing significant damage to unsuspecting users. Join the discussion | AlienVault OTX General | 09/22/2025, 12:16:16 UTC Added: 09/22/2025, 19:43:38 UTC |
The TAOTH campaign leveraged an abandoned Sogou Zhuyin IME update server and spear-phishing operations to deliver multiple malware families, primarily targeting users across Eastern Asia. Attackers employed sophisticated infection chains, such as hijacked software updates and fake cloud storage or login pages, to distribute malware and collect sensitive information. The campaign focused on high-value targets, including dissidents, journalists, researchers, and technology/business leaders in China, Taiwan, Hong Kong, Japan, South Korea, and overseas Taiwanese communities. Infrastructure and tool analysis link TAOTH to previously documented threat activity, showing shared C&C infrastructure, malware variants, and tactics indicative of a single, persistent attacker group with a focus on reconnaissance, espionage, and email abuse. Join the discussion | AlienVault OTX General | 08/28/2025, 14:51:55 UTC Added: 08/28/2025, 15:17:46 UTC |
The APT-C-55 (Kimsuky) group, a North Korean threat actor, has launched a new attack campaign targeting South Korea. They used a disguised Bandizip installation package to deliver malicious code and a VMP-protected HappyDoor trojan for espionage activities. The attack involves remote script loading, multi-stage malware deployment, and information theft. The malware collects sensitive data, including user information, system details, and files from specific directories. It also implements keylogging, screen capture, and mobile device monitoring functionalities. The attack methodology and infrastructure align with Kimsuky's historical patterns, including the use of similar scripts, backdoor families, and domain naming conventions. Join the discussion | AlienVault OTX General | 07/10/2025, 18:41:11 UTC Added: 07/10/2025, 22:01:06 UTC |
A critical vulnerability named DanaBleed was discovered in DanaBot's C2 server, causing memory leaks from June 2022 to early 2025. This bug, introduced in version 2380, exposed sensitive information including threat actor details, server data, and victim credentials. The leak resulted from uninitialized memory in the C2 protocol update. Researchers gained insights into DanaBot's operations, infrastructure, and affiliates. In May 2025, law enforcement dismantled DanaBot's infrastructure and indicted 16 individuals in Operation Endgame. The blog details the technical analysis of the vulnerability, its impact, and the type of data exposed through the memory leak. Join the discussion | AlienVault OTX General | 06/10/2025, 05:10:15 UTC Added: 06/10/2025, 09:09:36 UTC |
Showing 1 to 7 of 7 results