A compromised malware delivery server exposed an AI-assisted phishing infrastructure actively deployed against end users, providing insights into operationalization processes and automation techniques.
ACR Stealer infects enterprise customers through fake error messages with manipulated commands and steals browser data, credentials, and cloud content.
ACR Stealer exfiltrates browser credentials and Microsoft 365 content from enterprise environments via ClickFix lures by manipulating users to execute PowerShell commands directly.
ClickLock kills macOS applications in a continuous loop until users enter their password — a new extortion mechanism via LaunchAgents that requires systemic controls on macOS.
Around 290 fake GitHub repositories impersonate legitimate security and developer tools while distributing infostealers to compromise credentials and sensitive data from developers.
A compromised Jscrambler npm package containing infostealer malware was distributed by attackers in the npm registry and downloaded nearly 1,500 times.
The malware in jscrambler 8.14.0 is activated by the preinstall hook without explicit import or CLI command — installation alone is sufficient for execution.
The malware in jscrambler 8.14.0 is activated by the preinstall hook without explicit import or CLI command—installation alone is sufficient for execution.
Malware in jscrambler 8.14.0 is activated via the preinstall hook without explicit import or CLI command—installation alone is sufficient for execution.
PamStealer combines social engineering, native macOS functions, and Rust-based payloads to masquerade as a system process and steal passwords and clipboard contents.