Tag

#infostealer

38 stories taggedinfostealer.

Illustration for the story: SectopRAT Hidden Inside Legitimate Audio Software to Steal Passwords and Take Remote Control
Threat Intelligence

SectopRAT Hidden Inside Legitimate Audio Software to Steal Passwords and Take Remote Control

Fortinet's incident responders found a powerful remote-access trojan tucked inside a tampered copy of a real audio program. The malware can grab browser passwords, watch your screen, and hand full control of a Windows PC to criminals.

4 min read
Illustration: a dark workshop desk with a single unlit Windows laptop screen glowing pale blue
Threat Intelligence

Malware Lets Four AI Models Vote on What to Steal Next

Cisco Talos found a Windows sample that hands its decisions to a small panel of AI models. The lab copy does not run, but the idea is the story.

4 min read
Illustration: a modern silver laptop on a dark desk
Threat Intelligence

The macOS ClickFix Scam Learned to Hide From Researchers

Microsoft says the fake-fix lure now checks your browser before showing itself, and a related campaign is pushing a new remote-control tool called ChainScript.

4 min read
A split-screen view showing trusted application interfaces on one side morphing into malicious code structures on the other, with download progress indicators v
AI Security

Criminals Are Hiding Malware Inside Trusted AI Tools Like Claude and ChatGPT

Attackers are abusing Claude Artifacts, shared ChatGPT links and sponsored search ads to slip malware past users who trust the branding.

4 min read
A Reddit thread from a verified entertainment account flooded with copy-pasted scam messages, Windows and Mac malware warning popups appearing in separate brows
Threat Intelligence

Hijacked HBO Max Reddit account pushed 108 malware ads in 48 hours

A verified account was used to run a copy-paste scam that infected Windows and Mac users with password stealers and crypto-wallet thieves.

4 min read
A security researcher's workstation showing decompiled JavaScript code on the screen, Google login credentials highlighted, malware analysis tools open, network
Threat Intelligence

JSCeal: The Hidden JavaScript Malware Stealing Google Logins

Researchers at Check Point have pulled apart a stealthy piece of malware that hides inside compiled JavaScript, steals browser session cookies, and watches what victims do online.

4 min read
A criminal marketplace interface displayed on dark web browser, infected Windows systems listed as products with pricing and specifications, transaction confirm
Threat Intelligence

BraZetsu: The Python Toolkit Turning Hacked PCs Into Products for Sale

Researchers say the framework lets access brokers package infected Windows machines as ready-to-sell inventory on criminal marketplaces.

3 min read
A dual-monitor workstation displaying a compromised login session on one screen and an infostealer malware interface on the other, digital fingerprints and sess
Identity & Access

When an Employee's Password Shows Up in a Stealer Log, the Session Cookie Is the Real Problem

Infostealer malware grabs more than passwords. It grabs live logins, and that's what lets attackers walk past multi-factor prompts.

4 min read
A developer's machine with folder structure expanding across the screen, credential stealer malware scanning through 469 different storage locations simultaneou
Identity & Access

Shai-Hulud Worm Now Hunts 469 Places for Developer Secrets

A self-spreading credential thief has more than doubled the hiding spots it checks on developer machines, from 189 to 469.

4 min read
A compromised Windows desktop showing infostealer malware activity in background processes, Anthropic Claude login screen in foreground being accessed without c
Identity & Access

Anthropic warns Claude accounts are being hijacked by password-stealing malware

The AI company says common infostealer malware on customer PCs has been lifting active Claude login sessions, letting criminals sign in without a password and burn through usage limits.

3 min read
A text editor displaying seemingly innocent English word lists and passages, with hidden malware code visualized as faint glitching text beneath the surface, su
Threat Intelligence

WordlistLoader Hides Malware Inside Plain English Word Lists

A new delivery tool for a fast-growing password thief disguises harmful code as ordinary text, making it harder for security software to spot the infection before it takes hold.

3 min read
A developer's workspace with multiple monitors showing code repositories and package manager windows, with one screen displaying a compromised file alert overla
Vulnerabilities

Rust developers hit by supply-chain attack on arrayref crate

Attackers hijacked a maintainer account and slipped credential-stealing malware into three popular Rust libraries during a 1.5-hour window on August 20.

3 min read
A MacBook Pro on a desk with suspicious activity indicators on the screen, password manager notifications and browser tabs visible, representing credential thef
Threat Intelligence

AmnesiaStealer: New Mac Malware Quietly Drains Passwords and Browser Sessions

A newly identified piece of malicious software targeting Apple Mac computers can lift saved passwords, browser cookies, and sensitive keychain data, and it's written in a programming language that makes it harder for security tools to catch.

3 min read
A developer's workstation showing VS Code with the Extensions marketplace open, two nearly identical 'Solidity Pro' extension tiles displayed side-by-side, one
Threat Intelligence

Fake 'Solidity Pro' VS Code Extensions Caught Emptying Crypto Wallets

Two look-alike extensions posed as tools for Ethereum developers, then quietly installed wallet and credential stealers on the machines that trusted them.

3 min read
A laptop displaying a Snowflake cloud interface with financial transaction notifications and cryptocurrency wallet addresses visible on adjacent windows, police
Cloud Security

Canadian hacker admits to Snowflake data thefts that hit 165 companies and 100 million people

Connor Moucka pleaded guilty to stealing terabytes from Snowflake customer accounts that had no second login step, extorting $2.5 million in bitcoin from victims including AT&T and Ticketmaster.

4 min read
© 2026 Threat Vectr