< Back to situation

[REVISION HISTORY]

Information-stealing malware developments

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-09-03 04:15 UTC → 2026-09-05 01:52 UTC · added removed

Security researchers have identified two distinct several information-stealing malware strains targeting different operating systems and user behaviors. AmnesiaStealer, a Rust-based malware, targets macOS users through ‘ClickFix’ campaigns. It uses fake GitHub download pages to trick users into executing malicious terminal commands. The malware is capable of hijacking browser sessions by copying Chromium profiles and using a ‘stream_module’ to gain interactive remote control. It targets data including passwords, cryptocurrency wallets, Apple Notes, and Telegram sessions. RevStealer targets Windows users by masquerading as fake desktop applications, such as ‘Claude Opus 5 Free Desktop,’ distributed via GitHub and game cheat websites. This malware is designed to evade detection by checking for sandbox environments and attempting to add itself to the Microsoft Defender exclusion list. It specifically targets credentials from over 50 cryptocurrency wallets and 12 password managers, while using Polygon smart contracts as a backup command-and-control channel. Recent developments show that infostealer malware is being used to harvest active login sessions from Anthropic Claude users, allowing attackers to exhaust usage limits and make unauthorized charges. Identified malware families involved in these attacks include Vidar, Lumma, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer (AMOS) on macOS. Anthropic has responded by forcing session logouts, removing saved payment cards, and issuing refunds. Additionally, a large-scale campaign has been uncovered involving 19 popular extensions for Google Chrome and Microsoft Edge. Attackers purchased legitimate applications or created functional utilities and then injected malicious code via updates to siphon passwords and cryptocurrency wallets. One specific extension, ‘Enable Right Click & Copy’, reportedly affected nearly 70,000 users. While removed from official stores, these extensions remain active on infected machines and require manual uninstallation.

Versions

  1. 2026-09-05 01:52 UTC Information-stealing malware developments
  2. 2026-09-03 04:15 UTC Information-stealing malware developments

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.