infostealer13 articles
Fake OpenAI Codex Ads Are Serving Mac Malware Via Terminal Commands
Cybercriminals are running a malware campaign targeting Mac developers by placing fake sponsored Google ads for OpenAI Codex, directing victims to convincing but fraudulent download pages. Instead of providing an installer, the sites instruct users to run a terminal command that covertly triggers a multi-stage malware infection — a tactic known as "ClickFix" — ultimately deploying what appears to be the AMOS infostealer. A similar fake page impersonating Anthropic's Claude Code was also discovered sharing the same infrastructure, suggesting a broader campaign against developers seeking AI coding tools.
Threat Actor Claims Millions of Corporate Records Lifted from Azure Tenants
A threat actor called "TheHatman" is claiming to have stolen millions of employee records from the Microsoft Azure environments of major corporations including McDonald's, Vodafone, Tata Consultancy Services, and Kyndryl, with the data reportedly including sensitive details such as employee IDs, job titles, and accounts with Global Administrator privileges. Security firm Hudson Rock assessed the data as "highly likely authentic" but could not determine the exact method of access, suggesting possibilities such as infostealer malware, phishing, or weak multi-factor authentication. Tata Consultancy Services has denied finding credible evidence of a breach, stating the referenced information appears to be over four years old and limited to basic employee data.
Hacker Flogs Azure Directory Data From McDonald's, Vodafone and a Stack of Fortune 500 Names
A threat actor known as 'TheHatman' is selling data allegedly stolen from the Azure tenants of multiple Fortune 500 companies, including McDonald's, TCS, Vodafone, and Wyndham Hotels, with the McDonald's dataset alone containing over 1.7 million records. The data, which appears to have been exfiltrated using leaked credentials from a targeted infostealer campaign, includes sensitive employee information such as names, email addresses, job titles, and privileged account details. Security firm Hudson Rock warns the breach poses a serious risk, as the exposed data could enable attackers to conduct spear-phishing, business email compromise, and privilege escalation attacks against the affected organisations.
AmnesiaStealer: The macOS Malware That Watches You Browse in Real Time
is a newly discovered Rust-based macOS malware distributed via a fake GitHub page using ClickFix-style social engineering, tricking victims into running a malicious Terminal command. Once installed, it harvests sensitive data including browser databases, keychains, Apple Notes, and documents, while also attempting to bypass macOS's TCC framework to gain broader access. A particularly notable feature is its remote-control "stream module," which uses the Chrome DevTools Protocol to launch a hidden browser session, giving attackers live, interactive control over the victim's browsing activity.
ClickFix Malware Can Slowly Bleed Your Crypto Wallet Dry
ClickFix-style attacks are being used to deliver a Go-based macOS malware that steals browser passwords, Apple Keychain data, and cryptocurrency wallet contents, with the ability to gradually drain funds across multiple cryptocurrencies including Bitcoin, Ethereum, and Monero. The attack tricks victims into pasting a command into Terminal, which profiles the system, downloads a compatible payload, and uses a fake error prompt to harvest system credentials. The malicious infrastructure is linked to Aeza Group, a Russian bulletproof hosting provider sanctioned by the US, UK, and Australia.
Snowflake Breach Hacker Pleads Guilty: 100 Million Records, Stale Passwords, and No MFA
Connor Riley Moucka, 26, pleaded guilty to computer fraud, wire fraud, and identity theft charges related to the 2024 breaches of Snowflake customer accounts, which compromised at least 165 organizations and exposed records of over 100 million people. The attacks required no sophisticated exploits — attackers simply used old credentials harvested years earlier by infostealer malware on accounts with no multi-factor authentication enabled. Moucka faces a mandatory two-year minimum plus up to 30 years on additional charges and is due to be sentenced on October 27, 2025.
Meet Dolphin X: The Infostealer With an AI Profiler That Tells Crooks Which Victims Are Worth Robbing First
Varonis Threat Labs has discovered a new Windows malware called Dolphin X, sold on cybercrime forums, which targets over 300 applications and can steal credentials, cryptocurrency wallets, SSH keys, and cloud tokens. Its most notable feature is an AI Profiler that analyses victims' app usage, browsing history, and installed software to rank them by likely profitability, helping criminals prioritise their attacks — something researchers say has never been seen before in malware. Sold through a tiered subscription model starting at around $80 per month, the malware lowers the technical barrier for cybercriminals and includes advanced detection-evasion capabilities, prompting security experts to advise defenders to focus on behavioural threat detection rather than file signatures.
TELEPUZ: The Modular Malware Using Telegram, Steam, and a Blockchain to Phone Home
TELEPUZ is a newly discovered modular malware written in C that has been spreading since late April 2026 through ClickFix-style social engineering attacks, which trick users into pasting and executing malicious commands. Once installed, it employs extensive evasion techniques — including anti-VM checks, AMSI/ETW disabling, and obfuscation — before establishing contact with its command-and-control server via WebSockets to steal data, log keystrokes, capture screenshots, and execute commands. The malware uses multiple fallback methods to locate its C2 server, including Telegram, Steam, DNS queries, and a Polygon blockchain smart contract, and is believed to be an early-stage malware-as-a-service (MaaS) offering based on its high build volume and rapid development pace.
ACR Stealer Is Raiding Enterprise Networks and All It Needs Is for Someone to Press Enter
ACR Stealer, an infostealer active since 2024, is being distributed through ClickFix lures that trick users into pasting malicious commands into Windows' Run dialog, requiring no vulnerability or exploit to succeed. Once executed, the malware uses two delivery chains — one file-based and one nearly entirely in-memory — to steal browser passwords, session tokens, and Microsoft 365 documents, with techniques including payload concealment inside JPEG pixels and blockchain-based command-and-control infrastructure. Defenders are advised to block the paste-and-run vector via Group Policy, apply application control rules, revoke (not just rotate) compromised tokens, and hunt for indicators such as rundll32.exe making unexplained network connections or scheduled tasks disguised as software updates.
BusySnake: The Python Stealer Quietly Targeting Governments and Power Grids
A threat actor called Armored Likho has been conducting cyber espionage and financially motivated attacks against government agencies and energy sector organisations in Russia, Brazil, and Kazakhstan, using spear-phishing emails as the initial entry point. The group deploys a newly discovered Python-based malware called BusySnake Stealer, which harvests credentials, browser cookies, keystrokes, cryptocurrency wallets, and Telegram data, while evading detection through dynamic bytecode encryption and obfuscation techniques. Kaspersky has linked Armored Likho to the previously tracked Eagle Werewolf cluster, noting the group is actively refining its toolkit — including integrating reverse SSH tunnelling directly into the stealer — and may be using AI tools to assist in generating its first-stage payloads.
PamStealer: The macOS Malware That Actually Did Its Homework
Researchers at Jamf have discovered a novel macOS malware called PamStealer, which disguises itself as the Maccy clipboard manager and uses a two-stage infection chain — an AppleScript-based first stage and a Rust-written second stage — to stealthily steal credentials. It stands out by using macOS's built-in Pluggable Authentication Modules (PAM) interface to validate stolen passwords locally, avoiding the detectable system calls used by most comparable malware. The malware also employs additional evasion tactics such as impersonating legitimate macOS components, delaying suspicious prompts by up to 40 minutes, and bypassing macOS quarantine restrictions, illustrating the growing sophistication of Mac-targeted infostealers.
VEIL#DROP: How Attackers Are Hiding Malware Inside Google's Blogger
The VEIL#DROP attack chain uses a disguised JavaScript file to trigger a multi-stage malware infection, leveraging Google's Blogger platform to host payloads and bypass reputation-based security defences. The infection employs advanced evasion techniques including dynamic URL generation, runtime script mutation, fileless in-memory execution, and abuse of trusted Microsoft-signed binaries (Living-off-the-Land) to avoid detection. The ultimate goal is to deploy PureLogs Stealer, a .NET-based malware-as-a-service infostealer capable of harvesting sensitive data and potentially enabling deeper network compromise.
Reaper Malware Hits macOS: Steals Passwords, Drains Crypto Wallets, Then Quietly Moves In
A new macOS malware variant called Reaper, an updated version of the SHub stealer, targets users by spoofing trusted domains like Apple, Microsoft, and Google to steal passwords, cryptocurrency wallet credentials, and sensitive files. Unlike earlier versions, it bypasses Apple's Terminal entirely by using macOS Script Editor to execute its malicious payload, circumventing defences added in macOS Tahoe 26.4. The malware also establishes persistent backdoor access by disguising itself as a Google Software Update process, allowing attackers to remotely execute code on compromised machines every 60 seconds.