< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

3 clusters · 4 sources · 18 days · First seen · Last updated

Information-stealing malware developments

Overview

Security researchers have identified several information-stealing malware strains targeting different operating systems and user behaviors.

AmnesiaStealer, a Rust-based malware, targets macOS users through ‘ClickFix’ campaigns. It uses fake GitHub download pages to trick users into executing malicious terminal commands. The malware is capable of hijacking browser sessions by copying Chromium profiles and using a ‘stream_module’ to gain interactive remote control. It targets data including passwords, cryptocurrency wallets, Apple Notes, and Telegram sessions.

RevStealer targets Windows users by masquerading as fake desktop applications, such as ‘Claude Opus 5 Free Desktop,’ distributed via GitHub and game cheat websites. This malware is designed to evade detection by checking for sandbox environments and attempting to add itself to the Microsoft Defender exclusion list. It specifically targets credentials from over 50 cryptocurrency wallets and 12 password managers, while using Polygon smart contracts as a backup command-and-control channel.

Recent developments show that infostealer malware is being used to harvest active login sessions from Anthropic Claude users, allowing attackers to exhaust usage limits and make unauthorized charges. Identified malware families involved in these attacks include Vidar, Lumma, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer (AMOS) on macOS. Anthropic has responded by forcing session logouts, removing saved payment cards, and issuing refunds.

Additionally, a large-scale campaign has been uncovered involving 19 popular extensions for Google Chrome and Microsoft Edge. Attackers purchased legitimate applications or created functional utilities and then injected malicious code via updates to siphon passwords and cryptocurrency wallets. One specific extension, ‘Enable Right Click & Copy’, reportedly affected nearly 70,000 users. While removed from official stores, these extensions remain active on infected machines and require manual uninstallation.

Entities

Anthropic · RevStealer · Socket · Morphisec Threat Labs · GitHub

Timeline

  1. 9 days ago

    [TECHNOLOGY] 2 sources
    Cybersecurity threats target Anthropic Claude users and browser extensions

    Cybersecurity alerts warn of infostealer malware targeting Anthropic Claude sessions and malicious browser extensions for Chrome and Edge designed to steal passwords and cryptocurrency.

  2. 10 days ago

    [TECHNOLOGY] 2 sources
    RevStealer malware targets crypto wallets via fake Claude Opus 5 apps

    A new malware named RevStealer is targeting users via fake Claude Opus 5 desktop apps to steal cryptocurrency wallets, passwords, and sensitive browser data.

  3. 26 days ago

    [TECHNOLOGY] 5 sources
    AmnesiaStealer malware targets macOS users via browser hijacking

    AmnesiaStealer, a new macOS malware, uses ClickFix attacks to hijack browser sessions and steal sensitive data, including passwords, cryptocurrency wallets, and keychain information.

Sources

blockcast.it · geekyalgeria.com · generation-nt.com · srpskainfo.com

This summary has been updated 1 time: see revision history