CuraSec

tag: Infostealer · 19 items

2026-08-30 · BleepingComputer · source ↗ #infostealer#session-hijacking#ai-security
  • Engineer — Plan: Infostealers targeting developer AI-tool sessions is a realistic threat on dev machines. Audit active Claude API keys and session tokens for anomalous usage, and confirm your endpoint protection covers current infostealer families.
  • SOC/IR — Learn: Confirms infostealers (T1539) are expanding targeting to AI platform sessions, broadening the credential-theft surface. No IOCs or specific malware families disclosed, so no immediate detection action is possible.
  • Leader — Learn: Signals that AI tools are now routine infostealer targets, meaning compromised employee devices could expose corporate AI usage. No breach at a specific vendor; file as context for AI-tool acceptable-use and endpoint hygiene policy reviews.
  • Engineer — Plan: Audit installed Chrome/Edge extensions across your managed fleet and enforce an allowlist policy; no CISA KEV or active enterprise exploitation signal, but browser extension supply-chain risk is real for developer workstations.
  • SOC/IR — Act: Hunt for suspicious extension IDs from the reported malicious set in browser inventory logs and EDR telemetry; also look for ClickFix lure behavior (fake captcha/update prompts triggering clipboard/PowerShell execution) as a detection pattern since this reporting date.
  • Leader — Plan: Browser extension governance is a gap in most enterprise policies — use this as a prompt to task the team with drafting an approved-extension policy before the next audit cycle.
2026-08-25 · The Hacker News · source ↗ #malware#infostealer#clickfix
  • Engineer — Learn: ClickFix/FakeCaptcha campaigns now chain WordlistLoader into Amatera Stealer, illustrating how social-engineering lures bypass endpoint controls; no software to patch, but review user-facing browser security policies and endpoint AV coverage for stealer behavior.
  • SOC/IR — Plan: New malware families (WordlistLoader, SynkLoader, Amatera Stealer) using ClearFake/ClickFix delivery are emerging access-broker tools; no IOCs published yet, but queue detection rules for ClickFix script execution patterns and credential-harvesting C2 callouts when indicators surface.
  • Leader — Skip
2026-08-21 · BleepingComputer · source ↗ #supply-chain#rust#infostealer
  • Engineer — Act: Supply-chain compromise of a widely used Rust crate that executes malware at build time matches Act criteria even without KEV/EPSS signals. Audit your Cargo.lock for arrayref, identify any builds that ran against the compromised versions, rotate secrets accessible from affected build environments, and pin to a verified clean version or remove the dependency.
  • SOC/IR — Act: Build-time execution means any developer or CI runner that compiled code with the poisoned crate may be implanted with an infostealer — assume breach on those systems. Hunt for infostealer IOCs (check the BleepingComputer write-up for specifics) on developer workstations and CI/CD runners that use Rust, prioritizing the window since the account compromise occurred.
  • Leader — Act: A compromised popular Rust crate that stole credentials from developer machines is a potential breach event if your org uses Rust. Confirm whether arrayref appears in any internal Cargo.lock files, determine the affected build window, and have your team assess whether CI secrets or developer credentials were exposed before briefing leadership.
2026-08-17 · BleepingComputer · source ↗ #macos#infostealer#clickfix
  • Engineer — Learn: New macOS infostealer delivered via ClickFix social engineering adds interactive browser streaming capability — no software patch applies, but engineers managing macOS fleets should review endpoint controls and user-awareness posture around ClickFix-style lures. No KEV, PoC, or exploitation signals to trigger Act.
  • SOC/IR — Plan: Novel macOS infostealer with a remote browser-control streaming module represents a new TTP worth building detections for this quarter — develop rules for ClickFix delivery patterns and anomalous browser-streaming processes on macOS endpoints, but no published IOCs exist yet to run an immediate sweep.
  • Leader — Skip
2026-08-07 · BleepingComputer · source ↗ #macos#infostealer#clickfix
  • Engineer — Learn: ClickFix is a social-engineering technique (not a patchable CVE) that tricks users into pasting malicious commands; no enrichment signals confirm active enterprise targeting, but engineers on macOS should know that Keychain and browser credentials are in scope for this class of attack.
  • SOC/IR — Plan: Build or tune macOS endpoint detections for ClickFix lures — unusual clipboard-paste-to-terminal sequences and unsigned Go binaries executing in user context are the key behavioral signals; no IOCs are published yet, so monitor threat-intel feeds and queue this for detection engineering this quarter.
  • Leader — Learn: An active credential- and crypto-theft campaign targeting macOS is useful context for security awareness programs and endpoint policy reviews, but with no named vendor breach or regulatory trigger, no immediate leadership action is required.
2026-08-06 · Microsoft Security Blog · source ↗ #macos#infostealer#clickfix
  • Engineer — Learn: No patch or config action required; the shift to fingerprinting-gated delivery changes how malicious infra evades scanners, worth understanding when evaluating endpoint controls for macOS fleets.
  • SOC/IR — Plan: The new fingerprinting gate creates a hunting opportunity — build or tune detections for ClickFix-style clipboard-injection lures on macOS endpoints, and review proxy/DNS logs for infra that only responds to specific browser profiles.
  • Leader — Skip
2026-08-04 · BleepingComputer · source ↗ #infostealer#rat-malware#consumer
  • Engineer — Skip
  • SOC/IR — Learn: Consumer-targeted campaign delivering infostealer and RAT via fake gaming tools; lure technique is low-novelty but worth noting if the estate includes personal devices or BYOD endpoints where gaming software might appear.
  • Leader — Skip
2026-08-03 · SANS ISC · source ↗ #macos#infostealer#amos
  • Engineer — Learn: AMOS is an active macOS infostealer targeting credentials and sensitive files; the summary is too thin to confirm specifics, so read the full SANS ISC diary for infection chain details and any affected software or configuration indicators relevant to your macOS fleet.
  • SOC/IR — Plan: AMOS campaigns continue to hit macOS endpoints — review the full SANS ISC diary entry for IOCs and TTPs to build or tune macOS-targeted detections in your EDR and SIEM, particularly around credential-harvesting process behavior.
  • Leader — Skip
2026-07-21 · The Hacker News · source ↗ #ai-phishing#webdav-malware#infostealer
  • Engineer — Learn: The toolkit’s WebDAV-based execution chain and filename-spoofing techniques illustrate how AI lowers the bar for building polished lure campaigns; no patch or config change is indicated, but the delivery method is worth factoring into endpoint and proxy controls.
  • SOC/IR — Plan: Rapid7’s full toolkit dump provides campaign TTPs worth converting into detection rules — specifically hunt for WebDAV-hosted payload execution and filename-extension spoofing patterns in process telemetry; scope detections this quarter while IOC freshness holds.
  • Leader — Learn: Confirms AI is materially reducing attacker effort for phishing kit production; useful framing for a future board or risk-committee briefing on AI-enabled threats, but no immediate action is required.
2026-07-19 · BleepingComputer · source ↗ #infostealer#credential-theft#endpoint
  • Engineer — Learn: ACR Stealer targets browser-stored credentials and tokens — review whether your CI/CD pipelines or developer workstations enforce short-lived tokens and MFA to limit blast radius if credentials are harvested.
  • SOC/IR — Act: Microsoft is actively observing this campaign; hunt for ACR Stealer IOCs across EDR telemetry and SIEM, and tune detections for credential-access behaviors (browser credential dumping, token theft) across enterprise endpoints.
  • Leader — Plan: A confirmed surge targeting enterprise customers elevates infostealer risk on your risk register; consider briefing on phishing-resistant MFA adoption and reviewing credential hygiene posture this quarter.
2026-07-17 · The Hacker News · source ↗ #macos#infostealer#clickfix
  • Engineer — Learn: No CVE to patch — this is a social-engineering delivery chain (ClickFix-style Terminal paste) that installs LaunchAgent persistence. Engineers with macOS fleets should understand the vector and consider restricting user ability to run arbitrary Terminal commands via MDM policy.
  • SOC/IR — Plan: The two-stage behavior — LaunchAgent installation on cancel, then aggressive app-kill loop at next login — is detectable; build or tune rules for unexpected LaunchAgent creation from Terminal sessions and rapid repeated app-termination events on macOS endpoints.
  • Leader — Skip
2026-07-17 · BleepingComputer · source ↗ #macos#infostealer#credential-theft
  • Engineer — Learn: Novel macOS credential-harvesting technique worth understanding, but no KEV listing, PoC, or exploitation signals — no patch or config change required today. File for reference when evaluating EDR coverage on macOS developer endpoints.
  • SOC/IR — Plan: The forced-process-termination-then-password-prompt pattern is a detectable behavior sequence on macOS EDR; add detection logic for mass process kill events followed by a system authentication dialog this quarter. No IOCs published yet to sweep for.
  • Leader — Skip
2026-07-17 · Microsoft Security Blog · source ↗ #infostealer#credential-theft#clickfix
  • Engineer — Learn: ClickFix-delivered infostealers targeting browser credentials and auth tokens are relevant to understanding how attackers bypass browser security; no patch or config action required, but review whether privileged workstations restrict clipboard-execution lures.
  • SOC/IR — Act: Active enterprise campaigns from April–June 2026 using ClickFix lures to harvest credentials and tokens; hunt for ClickFix execution patterns (user-initiated PowerShell/cmd from browser context) and tune EDR/SIEM rules for ACR Stealer IOCs from Microsoft’s published analysis.
  • Leader — Learn: Infostealer campaigns targeting enterprise auth tokens are a credential-theft trend worth noting for board-level risk awareness, but this does not require immediate leadership action absent a confirmed incident in your environment.
2026-07-17 · The Hacker News · source ↗ #infostealer#clickfix#microsoft-365
  • Engineer — Plan: ClickFix is a social-engineering delivery vector, not a patchable vuln — review AppLocker/WDAC policies to restrict arbitrary Run-dialog execution, and audit M365 Conditional Access token-lifetime and revocation settings to limit stolen-session utility.
  • SOC/IR — Act: Microsoft Defender Experts documented two active delivery chains; hunt for PowerShell or cmd.exe spawned via user-initiated Run dialog (explorer.exe lineage), and sweep M365 Unified Audit Log for anomalous OAuth grants, bulk file access, or SharePoint/OneDrive exfiltration events since the campaign is live.
  • Leader — Plan: Session-token theft bypasses MFA and directly targets M365 documents — worth a leadership brief this quarter on lure-based infostealer risk, and a review of whether security-awareness training covers ClickFix-style social engineering.
2026-07-14 · BleepingComputer · source ↗ #supply-chain#npm#infostealer
  • Engineer — Act: Audit all projects and CI/CD pipelines for the malicious Jscrambler npm version; if found, treat the build environment as compromised and rotate any credentials or tokens accessible during that build.
  • SOC/IR — Act: Search CI/CD and build system logs for installations of the malicious Jscrambler package, then hunt for infostealer exfiltration activity (credential theft, unexpected outbound connections) on any hosts where it executed.
  • Leader — Plan: A supply-chain attack on a security vendor’s npm package (~1,500 downloads) underscores third-party software risk; confirm whether your org consumes Jscrambler’s npm package and, if so, request their incident timeline and impact report.
  • Engineer — Learn: The native C++ implementation and Apple notarization abuse represent a more evasion-resistant stealer design than typical macOS threats; no CVE or patch exists, but engineers managing macOS endpoints should verify their EDR (Jamf, CrowdStrike Falcon for Mac, etc.) detects this family before active campaigns emerge.
  • SOC/IR — Plan: The notarized-dropper technique complicates Gatekeeper-based detection signals; SOC teams with macOS in scope should plan detections around post-notarization behavioral indicators (local password validation, C++ stealers) and check whether Jamf Threat Labs has published IOCs or YARA rules to incorporate this quarter.
  • Leader — Skip
2026-07-14 · BleepingComputer · source ↗ #macos#infostealer#malware
  • Engineer — Learn: No KEV listing, PoC, or active exploitation signals; review macOS endpoint policies to ensure notarization and Gatekeeper controls are enforced to block unsigned impostor binaries.
  • SOC/IR — Plan: New macOS infostealer with a specific masquerade technique; build or tune detections for processes claiming to be Apple crash reporters that access keychain or crypto wallet paths outside expected Apple-signed binaries.
  • Leader — Skip
2026-07-12 · The Hacker News · source ↗ #supply-chain#npm#infostealer
  • Engineer — Act: A preinstall hook in jscrambler 8.14.0 drops and executes a cross-platform native infostealer — this is live supply-chain compromise. Audit all CI/CD pipelines and developer machines for installs of this exact version, remove or pin away from 8.14.0, and treat any affected environment as potentially credential-compromised.
  • SOC/IR — Act: Hunt for jscrambler 8.14.0 installs in npm audit logs, CI runner job histories, and artifact caches since July 11, 2026; on affected endpoints look for unexpected native binary drops or executions spawned from the npm install process, as infostealer data exfiltration may have already occurred.
  • Leader — Act: Confirm this week whether jscrambler 8.14.0 reached any company build pipeline or developer workstation; if so, treat as a credential-theft incident — initiate credential rotation and brief relevant stakeholders, since infostealers harvest tokens, SSH keys, and secrets stored on the machine.