All posts tagged: Malware

Mac Malware Can Control Active Browser Sessions

Mac Malware Can Control Active Browser Sessions

A routine-looking download can turn into a much bigger problem for Mac users. Jamf Threat Labs found an AmnesiaStealer campaign reaching macOS through a fake software download and capable of keeping attackers connected to browser sessions after infection. Researchers say the added access can extend the intrusion beyond the malware’s initial data theft. An attack begins with a user-run Terminal command, but its more unusual stage comes later, after AmnesiaStealer is already inside the system. A fake download opens the door on macOS Jamf Threat Labs traced the campaign to a counterfeit GitHub-style page offering a macOS download. Visitors are instructed to copy an encoded command into Terminal, using a ClickFix attack chain that relies on the target to execute the malicious instructions. Running the command triggers a shell script that downloads and launches AmnesiaStealer. The malware also attempts to obtain the user’s login password as it prepares to collect information from the system. Turning stolen data into browser access AmnesiaStealer first collects information stored on the infected device. Jamf found it targeting browser data and the macOS …

Fake The Odyssey Downloads Are Hiding Password-Stealing Malware

Fake The Odyssey Downloads Are Hiding Password-Stealing Malware

Cybercriminals are exploiting interest in The Odyssey to distribute Lumma Stealer through fake movie downloads. Bitdefender researchers identified malicious files posing as pirated copies of Christopher Nolan’s film that instead install the information-stealing malware. Lumma can target browser passwords, authentication cookies, payment information, cryptocurrency wallets, and other sensitive data stored on an infected device. The campaign uses the rush for pirated copies as its lure: users looking for a free movie download may instead receive an executable designed to look like the file they expected. How does this campaign work? According to Bitdefender, several versions of the Lumma Stealer malware are circulating online, disguised as pirated copies of The Odyssey. The observed malware used filenames resembling the release names people would expect for a movie download. Some of the observed names include: the odyssey 2160phd (2026) engsubs eztv.exe the odyssey 2026 1080p h264-djt.exe the odyssey 2026 1080p webrip-lama.exe Image: Bitdefender The deception continues at the file level. The executables can use icons associated with legitimate media players such as VLC. At the same time, Windows …

Google Restores Blogger Sites After Malware False Positives

Google Restores Blogger Sites After Malware False Positives

Google’s effort to keep malware off Blogger briefly ended up locking out legitimate publishers instead. Beginning Tuesday, August 4, hundreds of Blogger sites were flagged under the platform’s Malware and Similar Malicious Content policy. The incident resulted in blogs being locked, hidden from public view, or deleted despite showing no evidence of malware infection. For online platforms, the incident is a reminder that their ability to reach their audience ultimately depends on systems they neither control nor fully understand. When those systems make mistakes, even temporarily, the consequences can be catastrophic. False malware alerts lock Blogger sites Several Blogger site owners reported enforcement actions that left some publishers unable to access their sites. Others reported that their sites had disappeared from public view or been deleted. Image: Google Forum According to BleepingComputer, Google is aware of the incident, but has not released an official figure for the number of affected blogs. However, the outlet says the incident affected hundreds of sites running Google Blogger. As of the time of writing, Google’s own Blogger support forum …

124M Passwords Exposed as Infostealer Malware Hits Millions of Devices

124M Passwords Exposed as Infostealer Malware Hits Millions of Devices

The era of hacking corporate databases may be giving way to something far more direct. Have I Been Pwned has added a massive collection of infostealer malware records containing 124 million passwords and 56 million email accounts. The credentials came from stealer logs created by malware that harvests sensitive information from infected devices. The dataset offers a snapshot of how cybercriminal tactics are evolving. As infostealer malware becomes more widespread, attackers are increasingly bypassing organizations altogether and collecting credentials directly from users, creating fresh and simpler opportunities for account takeovers and broader cyberattacks. What happened and why it matters The most striking detail isn’t when the data appeared — it’s how much of it exists. 56 million unique email addresses and 124 million unique passwords were included in the infostealer dataset added to Have I Been Pwned. While the collection was added on June 15, the platform did not specify when the credentials were originally stolen. What is clear is that the records came from malware-infected devices rather than corporate breaches, reflecting a growing shift …

Fake Claude Code Installers Deliver Credential-Stealing Malware

Fake Claude Code Installers Deliver Credential-Stealing Malware

Developers searching for Claude Code installation instructions may be walking into a sophisticated malware campaign that masquerades as legitimate AI tooling documentation. Researchers found dozens of fake Claude Code and developer platform sites designed to steal credentials, API keys, and cryptocurrency. “The attack chain runs on the same unchecked trust that makes AI developer tools so easy to adopt,” said Straiker researchers in their analysis of the campaign. They added, “You copy a command. You paste it in your terminal. By then, it’s already too late.” Key takeaways of the fake Claude Code campaign Researchers identified more than 88 fake domains impersonating Claude Code and other developer platforms. The campaign uses SEO poisoning and Google ads to place malicious install pages above legitimate documentation. Attackers hide malicious commands inside seemingly legitimate installation instructions, often without disrupting the expected installation process. The malware specifically targets AI-related assets, including API keys, authentication tokens, and cloud development credentials. Inside the credential theft campaign The campaign has targeted users of popular AI and developer tools, including Claude Code, Cline, …

Techie Husband Installs Malware, Tracks Estranged Wife For 6 Months In Bengaluru | Bengaluru-news News

Techie Husband Installs Malware, Tracks Estranged Wife For 6 Months In Bengaluru | Bengaluru-news News

Last Updated:January 28, 2026, 15:39 IST Investigation suggests that the husband had been monitoring the woman’s phone for 6 months. He allegedly tracked her movements in real time and kept tabs on her communications. Police believe the malware was installed without the woman’s knowledge and remained active on her phone for an extended period. Image: Canva Cybercrime cases in Bengaluru often begin with a feeling rather than proof. A message arrives too quickly. A location is known too precisely. A private conversation is referenced without ever being shared. In one such case now under investigation, that uneasy pattern led a woman to uncover months of digital surveillance carried out by someone she once trusted the most. The case was registered at the Central Bengaluru CEN Crime Police Station following a complaint by a woman who is currently living separately from her husband due to marital disputes. The couple is also involved in an ongoing divorce petition. Over time, the woman began noticing that her estranged husband appeared to know details about her daily movements, phone …

LockBit Ransomware Group Reportedly Suffers Data Breach, Extortion Tactics Revealed

LockBit Ransomware Group Reportedly Suffers Data Breach, Extortion Tactics Revealed

LockBit, the notorious ransomware group, reportedly suffered a massive data breach on Wednesday. As per the report, the group’s dark web platform’s admin and affiliate panels were compromised to show a message and link to a MySQL database dump. The database reportedly contains 20 tables that include sensitive information around the cybercriminal group’s affiliate network, extortion tactics, details around malware builds, as well as nearly 60,000 Bitcoin addresses. Notably, this is the second time the ransomware group has been hacked, with the previous attack occurring in 2024. LockBit Hack Reveal Insights Into The Gang’s Workings The data breach was first spotted by X (formerly known as Twitter) user Rey, who posted a screenshot of the admin panel. All of the admin and affiliate panels were reportedly taken over to display the message, “Don’t do crime[.]CRIME IS BAD xoxo from Prague.” The text is followed by the MySQL link “paneldb_dump.zip.” According to a BleepingComputer report, the link leads to a MySQL file containing a massive database. The data reportedly features 20 different tables, where some tables …

Android Malware Exploits a Microsoft-Related Security Blind Spot to Avoid Detection

Android Malware Exploits a Microsoft-Related Security Blind Spot to Avoid Detection

This Motorola Moto G Power 5G shows the midnight blue color option. Image: Amazon New Android malware is using Microsoft’s .NET MAUI to fly under the radar in a new cybersecurity dust-up this week. Disguised as actual services such as banking and social media apps targeting Indian and Chinese-speaking users, the malware is designed to gain access to sensitive information. Cybersecurity experts with McAfee’s Mobile Research Team say that, while the threat is currently aimed at China and India, other cybercriminal groups could easily adopt the same method to target a broader audience. .NET MAUI’s hidden danger: Bypassing security Microsoft launched .NET MAUI in 2022, a framework that lets developers build apps for both desktops and phones using C#, replacing the now retired Xamarin tool. The intent of .NET MAUI was to make it easier to create apps that work across different platforms. Typically, Android apps are built with Java or Kotlin, and their code is stored in a format called DEX (Dalvik Executable); Android security systems are designed to scan these DEX files for …

FBI ‘Increasingly Seeing’ Malware Distributed In Document Converters

FBI ‘Increasingly Seeing’ Malware Distributed In Document Converters

Image: iStockphoto/domoyega Threat actors may attempt to distribute malware, including ransomware, by offering free document converters, according to a March 7 report from the FBI’s Denver office. “Agents are increasingly seeing” this type of scam. The scheme has been deployed globally, the FBI warned. How the document conversion scam works Threat actors behind the document converter scam disguise malicious software as a legitimate tool for file conversion. The software may claim to convert .doc files to .pdf files, merge multiple .jpg files into a single .pdf file, or download MP3 or MP4 audio files. In most cases, the downloaded software performs the advertised conversion. However, it also grants the attacker access to the victim’s computer. Once installed, the malware allows threat actors to download additional malicious software or access files submitted for conversion. If these files contain identifying information —  such as dates of birth, social security numbers, or phone numbers — the threat actor may exploit them for identity theft. The attacker could scrape the submitted files for banking information, seed phrases and other …

New Mac Malware Poses as Browser Updates

New Mac Malware Poses as Browser Updates

A new macOS malware called FrigidStealer is spreading through fake browser update alerts, allowing attackers to steal sensitive data, according to research from Proofpoint. This sophisticated campaign, embedded in legitimate sites, tricks users into bypassing macOS security measures. Once installed, the malware extracts browser cookies, stored passwords, cryptocurrency-related files, and Apple Notes – potentially exposing both personal and enterprise data. Two newly identified threat actors operate parts of these web-inject campaigns: TA2726, which may act as a traffic distribution service for other threat actors. TA2727, a group that distributes FrigidStealer and malware for Windows and Android. They may use fake update alerts to enable malware and are identifiable by their use of legitimate websites to send scam update alerts. Both threat actors sell traffic and distribute malware. Fake updates trick Mac users into bypassing security The update scam includes deceptive instructions designed to help attackers evade macOS security measures. At the end of January 2025, Proofpoint found that TA2727 used scam update alerts to place information-stealing malware on macOS devices outside of the United States. …