Threats Tagged 'stealer'
View all threats tagged with 'stealer'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'stealer'
Click on any threat for detailed analysis and mitigation recommendations
A sophisticated macOS malware campaign leverages ClickFix social engineering to infect victims. The attack begins with a fake CAPTCHA prompt delivered via email links, tricking users into executing malicious commands in Terminal. This downloads a profiling script that collects system information and deploys architecture-specific Go-based Mach-O payloads. The stealer targets browser passwords, Apple Keychain credentials, and cryptocurrency wallets. Its most notable feature is a DRAIN function that gradually siphons cryptocurrency from victims' wallets by redirecting portions to attacker-controlled accounts. The malware supports Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. Infrastructure analysis reveals hosting through Aeza Group, a sanctioned Russian bulletproof hosting provider. The malware achieves persistence through macOS Background Task Management and uses various evasion techniques including Gatekeeper bypass and credential harvesting via fake system prompts. Join the discussion | AlienVault OTX General | 08/06/2026, 17:35:59 UTC Added: 08/07/2026, 10:11:41 UTC |
The article exposes a sophisticated scam targeting Minecraft players through fake 'grief-free' server communities. The SugarSMP website, promising a safe gaming experience, was found to distribute malware-infected mod packs. The malware, named Spark stealer, steals sensitive data including Discord tokens, browser credentials, and crypto wallet information. The threat actors employ social engineering tactics to maintain their fake community's reputation and remove warnings about their activities. Multiple similar websites were discovered, all hosting various types of malware. The scam's persistence mechanisms and social engineering techniques are detailed, along with remediation steps for affected users. Join the discussion | AlienVault OTX General | 03/18/2026, 10:42:02 UTC Added: 03/18/2026, 11:27:29 UTC |
A new campaign exploits OpenClaw skills to distribute the Atomic MacOS Stealer (AMOS). This evolution in supply chain attacks manipulates AI agentic workflows to install malware. The campaign spans multiple repositories with hundreds of malicious skills uploaded to ClawHub and SkillsMP. The infection chain begins with a seemingly harmless SKILL.md file that installs a prerequisite, leading to the download of a Mach-O universal binary. This AMOS variant steals extensive data, including credentials, browser data, cryptocurrency wallets, and various user documents. It lacks system persistence but expands its reach by exfiltrating Apple and KeePass keychains. The malware uses sophisticated encryption schemes and targets multiple browsers and cryptocurrency wallets. Join the discussion | AlienVault OTX General | 02/23/2026, 22:38:38 UTC Added: 02/24/2026, 09:01:20 UTC |
A widespread campaign is distributing the RenEngine loader malware disguised as pirated games and software. The loader uses a modified Ren'Py game engine to deliver payloads like Lumma and ACR stealers. It employs sophisticated techniques including sandbox evasion, process injection, and modular design. The infection chain involves decrypting and launching malicious code through legitimate applications. RenEngine has affected users globally, with Russia, Brazil, Turkey, Spain and Germany most impacted. The campaign highlights risks of pirated software and the need for robust security measures. Join the discussion | AlienVault OTX General | 02/11/2026, 16:29:19 UTC Added: 02/11/2026, 22:01:15 UTC |
A sophisticated malware campaign exploits user trust in AI platforms to deliver the AMOS stealer. Attackers use SEO poisoning to surface malicious ChatGPT and Grok conversations offering 'helpful' macOS disk cleanup advice. These conversations contain Terminal commands that, when executed, deploy AMOS, a multi-stage malware that harvests credentials, escalates privileges, and establishes persistence. The attack bypasses traditional security measures by leveraging legitimate platforms and user behavior, making it particularly insidious. AMOS targets cryptocurrency wallets, browser data, and system information, exfiltrating sensitive data to attacker-controlled servers. This campaign represents a significant evolution in social engineering techniques, exploiting the growing reliance on AI assistants for technical guidance. Join the discussion | AlienVault OTX General | 12/10/2025, 12:06:40 UTC Added: 12/10/2025, 14:37:52 UTC |
A sophisticated campaign targeting macOS developers has been uncovered, utilizing fake websites impersonating trusted platforms like Homebrew, TradingView, and LogMeIn to distribute Odyssey Stealer and AMOS malware. The attackers employ social engineering tactics, prompting users to paste base64-encoded commands in Terminal, which downloads malicious payloads. Over 85 phishing domains were identified, linked through shared SSL certificates and infrastructure. The campaign's infrastructure includes long-standing IP addresses showing multi-year activity. The malware attempts privilege escalation, performs anti-analysis checks, and disrupts backup services. This coordinated operation demonstrates the attackers' ability to adapt tactics and maintain persistence in the macOS ecosystem. Join the discussion | AlienVault OTX General | 10/16/2025, 17:53:01 UTC Added: 10/16/2025, 21:28:49 UTC |
TA585 is a sophisticated cybercriminal threat actor that operates its entire attack chain, from infrastructure to email delivery and malware installation. The actor demonstrates innovation in the evolving cybercrime landscape, using unique web injection campaigns and complex filtering techniques. TA585 frequently delivers MonsterV2, a versatile malware with remote access trojan, loader, and stealer capabilities. MonsterV2 is used by multiple threat actors and avoids infecting computers in Commonwealth of Independent States countries. The malware is actively maintained and updated, with pricing ranging from $800 to $2,000 per month. TA585's campaigns often involve compromised websites, fake CAPTCHAs, and GitHub-themed attacks to deliver various payloads. Join the discussion | AlienVault OTX General | 10/14/2025, 03:39:57 UTC Added: 10/14/2025, 09:06:43 UTC |
Rhadamanthys, a complex multi-modular stealer, has released version 0.9.2 with significant updates. The malware now uses PNG files to deliver payloads, implements new evasion techniques, and introduces changes to its custom executable formats. Key modifications include a new message box mimicking Lumma stealer, updates to string encryption, and enhanced configurability. The malware continues to evolve, focusing on refinements and customization options while maintaining its core design. These changes aim to disrupt analysis tools and detection methods. The authors are professionalizing their operation, treating Rhadamanthys as a long-term business venture with tiered pricing and expanded product offerings. Join the discussion | AlienVault OTX General | 10/01/2025, 20:28:13 UTC Added: 10/01/2025, 21:44:06 UTC |
Olymp Loader is a recently emerged Malware-as-a-Service offering advertised on underground forums since June 2025. Developed by a team called OLYMPO, it's written in assembly language and marketed as fully undetectable. The loader executes other malware on victim systems and provides built-in stealer modules for browsers, Telegram, and crypto wallets. It enables rapid feature updates and fast adoption by cybercriminals. The malware has evolved from an initial botnet concept to focus on loader and crypter functionalities. Distribution methods include disguising as legitimate software and using other malware like Amadey as initial access. Post-infection payloads primarily include credential stealers and remote access tools. Join the discussion | AlienVault OTX General | 09/29/2025, 08:06:08 UTC Added: 09/29/2025, 08:46:55 UTC |
This analysis examines a campaign distributing Atomic macOS Stealer (AMOS), targeting macOS users through fake 'cracked' applications. Attackers use two main delivery methods: malicious .dmg installers and terminal commands that bypass Gatekeeper protection. AMOS employs rotating domains to evade detection and steals a wide range of sensitive data, including credentials, browser information, cryptocurrency wallets, and system files. The campaign demonstrates sophisticated tactics, adapting to macOS security improvements and leveraging social engineering. The report emphasizes the importance of comprehensive endpoint detection, user education, and defense-in-depth strategies to combat such threats. Join the discussion | AlienVault OTX General | 09/04/2025, 17:54:49 UTC Added: 09/04/2025, 21:23:56 UTC |
Showing 1 to 10 of 18 results