Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
3 clusters · 4 sources · 18 days · First seen · Last updated
Information-stealing malware developments
Overview
Security researchers have identified several information-stealing malware strains targeting different operating systems and user behaviors.
AmnesiaStealer, a Rust-based malware, targets macOS users through ‘ClickFix’ campaigns. It uses fake GitHub download pages to trick users into executing malicious terminal commands. The malware is capable of hijacking browser sessions by copying Chromium profiles and using a ‘stream_module’ to gain interactive remote control. It targets data including passwords, cryptocurrency wallets, Apple Notes, and Telegram sessions.
RevStealer targets Windows users by masquerading as fake desktop applications, such as ‘Claude Opus 5 Free Desktop,’ distributed via GitHub and game cheat websites. This malware is designed to evade detection by checking for sandbox environments and attempting to add itself to the Microsoft Defender exclusion list. It specifically targets credentials from over 50 cryptocurrency wallets and 12 password managers, while using Polygon smart contracts as a backup command-and-control channel.
Recent developments show that infostealer malware is being used to harvest active login sessions from Anthropic Claude users, allowing attackers to exhaust usage limits and make unauthorized charges. Identified malware families involved in these attacks include Vidar, Lumma, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer (AMOS) on macOS. Anthropic has responded by forcing session logouts, removing saved payment cards, and issuing refunds.
Additionally, a large-scale campaign has been uncovered involving 19 popular extensions for Google Chrome and Microsoft Edge. Attackers purchased legitimate applications or created functional utilities and then injected malicious code via updates to siphon passwords and cryptocurrency wallets. One specific extension, ‘Enable Right Click & Copy’, reportedly affected nearly 70,000 users. While removed from official stores, these extensions remain active on infected machines and require manual uninstallation.
Entities
Anthropic · RevStealer · Socket · Morphisec Threat Labs · GitHub
Timeline
-
9 days ago
[TECHNOLOGY] 2 sourcesCybersecurity threats target Anthropic Claude users and browser extensionsCybersecurity alerts warn of infostealer malware targeting Anthropic Claude sessions and malicious browser extensions for Chrome and Edge designed to steal passwords and cryptocurrency.
-
10 days ago
[TECHNOLOGY] 2 sourcesRevStealer malware targets crypto wallets via fake Claude Opus 5 appsA new malware named RevStealer is targeting users via fake Claude Opus 5 desktop apps to steal cryptocurrency wallets, passwords, and sensitive browser data.
-
26 days ago
[TECHNOLOGY] 5 sourcesAmnesiaStealer malware targets macOS users via browser hijackingAmnesiaStealer, a new macOS malware, uses ClickFix attacks to hijack browser sessions and steal sensitive data, including passwords, cryptocurrency wallets, and keychain information.
Sources
blockcast.it · geekyalgeria.com · generation-nt.com · srpskainfo.com
This summary has been updated 1 time: see revision history