Skip to main content

Threats Tagged 'infostealer'

View all threats tagged with 'infostealer'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: infostealer

Threats Tagged 'infostealer'

Click on any threat for detailed analysis and mitigation recommendations

PolinRider operators compromised a GitHub account to insert malicious code into development versions of visanduma/nova-two-factor, a Packagist package with over 700,000 downloads. The campaign spreads through compromised developer accounts and Git repositories across multiple ecosystems including npm, PyPI, Go modules, Packagist, and Chrome extensions. The operators use Git history rewriting, payload concealment in configuration files and font files, automatic execution through IDE tasks, and staged payload delivery via dead-drop mechanisms like EtherHiding and NullReceiver. Primary infection occurs through Git-based collaboration rather than direct package registry compromise, with PHP projects targeted using obfuscated JavaScript executed through shell_exec. The campaign appears linked to North Korean operators focused on cryptocurrency theft.

Join the discussion

Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack.

Join the discussion

An emerging infostealer tracked as REVSTEALER under REF2859 has gained significant momentum with approximately 4,700 samples identified over the past year. The malware features comprehensive credential harvesting capabilities targeting browsers, VPN applications, password managers, cryptocurrency wallets, and gaming platforms. It incorporates sophisticated anti-analysis mechanisms including a weighted sandbox scoring system and uses Polygon blockchain-based dead drops for resilient infrastructure management. Distribution occurs primarily through social engineering campaigns targeting gamers via compromised YouTube channels advertising fake game cheats, though samples also impersonate legitimate software like Slack and qBittorrent. The malware delivers four additional modules extending capabilities to include wallet theft, clipboard manipulation, reverse proxy functionality, and cryptocurrency mining deployment. Most samples employ VMProtect packing and feature an App-Bound Encryption bypass using debugger-...

Join the discussion
0

A Reddit user observed an advertisement on Reddit impersonating the HBO Max brand to distribute a macOS application that acts as an infostealer malware. The ad appeared to be posted by a verified user account, which is suspected to be compromised. The malicious download leads to an executable capable of account compromise. The reporter has notified Reddit and HBO Max about the incident.

Join the discussion

In July 2026, multiple APT campaigns targeted South Korean entities using spear phishing emails with malicious LNK files. Seven distinct attack types employed various techniques such as PowerShell scripts, AutoIt programs, DLL side-loading, and curl.exe downloads. Malware was distributed via platforms like GitHub, Google Drive, and Dropbox, disguised as legitimate documents or resumes. The campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate sensitive information and maintain persistence through Task Scheduler entries. Communication with command and control servers used PubNub channels with Base64-encoded data. The attacks focused on deceiving victims with work-related content to execute malicious payloads.

Join the discussion

Cybercriminals are exploiting the hype around Grand Theft Auto VI by creating fake websites that impersonate official Rockstar Games promotional material. These sites offer a GTA 6 demo download which is actually a Vidar infostealer malware. The malware steals sensitive browser data including passwords, cookies, session tokens, autofill data, and FTP credentials from multiple browsers. It uses legitimate browser binaries in headless mode to bypass protections and steal data more effectively. Stolen session tokens can bypass two-factor authentication, allowing persistent unauthorized access even after password changes. This campaign leverages recent GTA 6 leaks to lure victims.

Join the discussion

On 5 May 2026, a Jamf Protect deployment blocked a download attempt from jacksonvillemma[.]com, four days after the operator's previous MacSync C2 was publicly disclosed. The new C2's TLS certificate was issued within 24 hours of that disclosure. Analysis revealed a Stage 2 zsh loader containing a static api-key value observed across four distinct C2 domains spanning December 2025 to May 2026. URI-pattern pivoting through any.run identified eleven additional candidate C2 domains dating back to February 2026, suggesting parallel infrastructure operation rather than sequential rotation. The loader exfiltrates macOS credentials, browser data, and cryptocurrency wallets, and transmits the victim's account password in cleartext via URL query strings, making it visible in web proxy logs.

Join the discussion

WatchGuard Threat Lab identified an active malware-as-a-service campaign leveraging ErrTraffic framework to distribute multiple threats through compromised WordPress websites. The operation employs ClickFix social engineering techniques and EtherHiding, which uses Polygon blockchain smart contracts to conceal command-and-control infrastructure dynamically. The campaign delivers various threats including Vidar infostealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader through multiple delivery methods such as DLL side-loading, process injection, and reflective loaders. Attackers exploit legitimate Windows binaries as LOLBINs, perform anti-analysis checks, create remote threads in browsers to bypass security features like Chrome's Application-Bound Encryption, and utilize various evasion techniques including code virtualization and RunPE. The framework is advertised by user LenAI on cybercrime forums and incorporates a Traffic Distribution System enabling affiliates to monetize victims...

Join the discussion

In February 2026, an active malware delivery campaign named Powercat was observed distributing infostealer malware disguised as utility or cheat software for popular PC games including Roblox, Minecraft, and Grand Theft Auto V. The multi-stage infection chain begins with an initial executable that profiles victims and establishes persistence, followed by a Java-based loader that deploys the final infostealer payload. The malware targets cryptocurrency wallets (Exodus, Atomic, Monero-Gui), browser data from Chromium-based applications, Discord tokens, and gaming accounts with payment information. It includes surveillance capabilities such as keylogging, webcam capture, and screen recording. The campaign particularly targets children who frequent gaming platforms and pay-to-cheat websites, with evidence suggesting collected personal information may be used for blackmail or coercion into illegal activities.

Join the discussion

A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.

Join the discussion

Showing 1 to 10 of 147 results

Filters:Tag: infostealer
Page 1 of 15
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses