Skip to content

Topic

Infostealer Malware

Malware families whose primary objective is harvesting credentials, wallets, documents and browser data for exfiltration.

Current stories

build1 publisher

ANSSI traces the DGFIP tax breach to stolen passwords on password-only staff portals

ANSSI says an attacker used dozens of stolen DGFIP staff passwords on password-only portals to take data on over 600,000 French taxpayers and businesses. For other operators, the fixes are login checks on devices they do not manage and a password reset that also ends live sessions.

Publishers:dev.to

Reality

Evidence58
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence55
security1 publisher

Australian Signals Directorate tells AI customers to guard their own keys and sessions

Australia's Signals Directorate says attackers are using stolen AI API keys, tokens and hijacked sessions to get into organisations' AI services. Its guidance tells customers to protect those credentials themselves. In one reported case, a stolen key ran up about US$600,000 in model credits over three weeks.

Reality

Evidence45
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence50
security5 publishers

Stolen logins, not a SaaS breach: nine enterprises' Entra directories are now for sale

A seller using the name TheHatman is offering employee directory exports from nine named enterprises. Hudson Rock ties the theft to infostealer credentials, not a compromise of the provider.

Perspective Coverage

5 publishers
Builder
Builder 25%
Operator
Operator 61%
Investor
Investor 14%

Reality

Evidence55
Adoption
Insufficient
Hype gap+30
Incentives50
Confidence60
security3 publishers

WeedHack lost its C2 and kept its funnel: ten fake Minecraft sites still convert victims

McAfee says the WeedHack stealer's control server is dead and its renter dashboard gone, but ten impersonation sites and the search rankings behind them are still delivering victims.

Perspective Coverage

3 publishers
Builder
Builder 18%
Operator
Operator 77%
Investor
Investor 5%

Reality

Evidence55
Adoption40
Hype gap+15
Incentives55
Confidence60
security7 publishers

Commodity infostealers are now cashing out stolen Claude sessions

Anthropic is signing affected users out, stripping saved payment methods and issuing refunds after someone began pulling Claude cookies out of ordinary stealer logs and spending other people's quota.

Perspective Coverage

7 publishers
Builder
Builder 19%
Operator
Operator 72%
Investor
Investor 9%

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives40
Confidence60
security5 publishers

A hijacked HBO Max Reddit account pushed 108 ClickFix ads to Windows and macOS users

Hudson Rock and ADAMnetworks link the ads to an operation they call PasteSwitch, which hands Windows and macOS visitors different paste-this-command lures and swaps payloads on the backend depending on who arrives.

Perspective Coverage

5 publishers
Builder
Builder 29%
Operator
Operator 65%
Investor
Investor 6%

Reality

Evidence74
Adoption
Insufficient
Hype gap+8
Incentives50
Confidence72
security3 publishers

Compromised Ukrainian business sites are serving a ClickFix lure that installs through msiexec

Arctic Wolf Labs found injected iframes on real Ukrainian business sites showing a Ukrainian-language fake Cloudflare check that copies a Windows Installer command for the visitor to paste into Run. Its exposed panel logged 557 views.

Perspective Coverage

3 publishers
Builder
Builder 30%
Operator
Operator 64%
Investor
Investor 6%

Reality

Evidence68
Adoption14
Hype gap+8
Incentives35
Confidence64
security4 publishers

Rapuncel ships a Microsoft-attested kernel driver built to terminate 145 security products

LastPass traced a fake Authenticator hosted on GitHub to a months-long impersonation campaign that spoofed at least 40 organizations, including its own brand. The server steering victims to the download was still being updated in September.

Perspective Coverage

4 publishers
Builder
Builder 27%
Operator
Operator 64%
Investor
Investor 9%

Reality

Evidence68
Adoption
Insufficient
Hype gap+15
Incentives40
Confidence70

Earlier coverage

  1. Forged government requests pulled passport data out of Revolut for five months

    Security · September 17, 2026 · 1 publisher

  2. Software priced 610,000 stolen Roblox accounts by what was inside them

    Security · September 16, 2026 · 1 publisher

  3. Three malware campaigns stage their lure pages on Claude and ChatGPT share links

    Build · September 11, 2026 · 1 publisher

  4. REVSTEALER-linked module LockAppHost disables 18 Windows update and malware-removal mechanisms before mining

    Security · September 7, 2026 · 1 publisher

  5. Talos splits security burnout into four injuries with four different fixes

    Security · September 10, 2026 · 1 publisher

  6. Replayed session cookies bypassed the conditional access that blocked stolen passwords

    Security · September 10, 2026 · 1 publisher

  7. Stealer logs now carry AI session tokens that replay straight past MFA

    Security · September 9, 2026 · 1 publisher

  8. Anthropic suspended a consultant's Claude account for two weeks to stop a token thief

    Product · September 8, 2026 · 1 publisher

  9. Talos ties a fake Google CAPTCHA to a DLL executing from a remote WebDAV share

    Security · September 8, 2026 · 1 publisher

  10. Talos found ClickFix operators moving their skimmer into a Tampermonkey userscript

    Product · September 8, 2026 · 1 publisher

  11. Anthropic says everyday infostealers are lifting live Claude sessions off victim machines

    Security · September 4, 2026 · 1 publisher

  12. RevStealer spread via fake free Claude Opus 5 desktop build on GitHub

    Security · September 1, 2026 · 2 publishers

  13. Fake macOS troubleshooting posts route infostealers past Gatekeeper

    Leadership · August 31, 2026 · 1 publisher

  14. ClickFix scales by asking employees to paste the command themselves

    Leadership · August 31, 2026 · 1 publisher

  15. Anthropic wipes saved cards after infostealers copy Claude login sessions

    Product · August 31, 2026 · 1 publisher

  16. The fake Qwen repo undershot its advertised weights by a factor of 34,000

    Invest · August 28, 2026 · 1 publisher

  17. GitVenom dressed hundreds of repositories over several years to ship AsyncRAT and Quasar

    Build · August 27, 2026 · 1 publisher

  18. WSL is a working bridge, and npm hygiene stops at the container wall

    Security · August 26, 2026 · 1 publisher

  19. A trailer date is a campaign schedule: fake GTA 6 sites are selling stolen session cookies

    Security · August 24, 2026 · 1 publisher

  20. Google: Russia-linked crews get targets to hand over app passwords, OAuth codes and WhatsApp devices

    Build · August 21, 2026 · 1 publisher

  21. Agent Tesla v4 hides in emoji and never hits disk: an email-rule problem, not a new-malware one

    Security · August 21, 2026 · 2 publishers

  22. AmnesiaStealer drives your own browser, so session theft is the real macOS loss

    Build · August 14, 2026 · 1 publisher