news.mlab.sh
Back to the feed
malware

Possible ACR Stealer From Page Impersonating Claude, (Tue, May 26th)

High
Image: SANS Internet Storm Center
Summary

This report details the discovery of a fake Claude webpage distributing the ACR Stealer malware, targeting macOS and Windows users. The initial infection vector involves malicious ads leading to the deceptive site, which then downloads a ZIP archive containing a PowerShell script. Analysis reveals the malware utilizes a C2 domain for post-infection communication and employs techniques to evade detection.

Read the full article at SANS Internet Storm Center

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.