threat-intel L’IA pirate qui promet anonymat et zéro filtre A French-language security news outlet, ZATAZ, tested DONG, an AI service claiming to offer anonymity and unfiltered content generation. The service allows users to create tools like HTML infostealers and generate explicit images without restrictions, raising concerns about its potential misuse by malicious actors. DON… ZATAZ · 2d ago High aianonymityinfostealer
threat-intel Foul Language: WordlistLoader Disguises Malware as Ordinary Text A new malware loader called WordlistLoader is being used to deliver the Amatera infostealer, primarily through ClickFix-style campaigns. WordlistLoader disguises malicious code using lists of ordinary English words, allo… Dark Reading · 6d ago High malwareloaderinfostealer
threat-intel Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People A former Snowflake customer account manager, Connor Riley Moucka, pleaded guilty to computer fraud and wire fraud, admitting to stealing data and extorting victims. The breaches impacted at least 165 organizations and ex… The Hacker News · Aug 6, 2026 High CAUNinfostealerpasswordcredential
threat-intel ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files ACR Stealer, an infostealer active since 2024, is leveraging deceptive lures – primarily mimicking Claude AI assistant pages and fake CAPTCHAs – to steal browser credentials, Microsoft 365 files, and sensitive documents.… The Hacker News · Jul 17, 2026 High infostealerdeceptive lureransomware
threat-intel ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories This week’s security news is a mixed bag, encompassing a range of threats from sophisticated ransomware attacks to deceptive software distribution and widespread surveillance techniques. A new ransomware family, Spirals,… The Hacker News · Jul 16, 2026 High CVE-2026-46817CVE-2023-4346CVE-2026-35273NESPPOransomwareinfostealerbrandjacking
threat-intel New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password A new macOS infostealer, dubbed ClickLock Stealer, is actively targeting users by forcing them to enter their passwords repeatedly through a loop of killing apps. The malware, a copy of GSocket, uses a deceptive Cloudfla… The Hacker News · Jul 16, 2026 High EUmacosinfostealerpassword
supply-chain Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install A malicious npm package, jscrambler 8.14.0, was released with a hidden infostealer that silently dropped and executed during installation. The package, pushed by a compromised account, included a Rust-based stealer targe… The Hacker News · Jul 11, 2026 High npmsupply-chainrust
malware Vidar Infostealer Hammers SMBs via Malvertising Campaign A financially motivated operation is using malvertising to deliver a two-for-one malware payload – the Vidar infostealer and XMRig cryptominer – to consumers and SMBs globally. The campaign employs sophisticated evasion… Dark Reading · Jul 8, 2026 High USEUmalvertisingmaascryptomining
threat-intel 'BusySnake' Infostealer Slithers into Critical Infrastructure Networks The threat group Armored Likho, operating under the name 'BusySnake,' has infiltrated critical infrastructure networks across Russia, Brazil, and Kazakhstan. This group is leveraging a sophisticated infostealer to steal… Dark Reading · Jul 6, 2026 High RUBRKZinfostealercritical infrastructurenation-state
apt Armored Likho APT Targeting Government, Electric Power Entities The Armored Likho APT group is actively targeting government and electric power entities across multiple countries, including Russia, Brazil, and Kazakhstan. The group utilizes a diverse toolkit of malware, including RAT… SecurityWeek · Jul 6, 2026 High RUBRKZaptspear-phishingrat
threat-intel Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign The Securelist report details a new cyber espionage campaign conducted by the Armored Likho (Eagle Werewolf) APT group, targeting government agencies and the electric power sector globally. The group utilizes a sophistic… Securelist · Jul 3, 2026 High RUBRKZaptphishinginfostealer
threat-intel Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer A sophisticated cyberattack has been uncovered involving hijacked npm and Go packages designed to deploy a Python-based information stealer. Attackers leveraged a VS Code task trigger to execute malicious code disguised… The Hacker News · Jun 29, 2026 High KPvscodenpmfont-file
threat-intel Three ‘cybercrime as a service’ operations undercut by Microsoft, law enforcement A coordinated international effort, led by Microsoft and Europol, successfully dismantled a significant cybercrime-as-a-service infrastructure used by multiple threat actors. The operation resulted in the seizure of subs… The Record · Jun 24, 2026 High RUcybercrime-as-a-servicesupply chaininfostealer
threat-intel More Malicious OpenClaw Skills Threaten AI Supply Chain A recent investigation by Palo Alto Networks' Unit 42 revealed five malicious skills hidden within OpenClaw's ClawHub marketplace, a platform for AI agent skills. These skills, including infostealers, detection evasion t… Dark Reading · Jun 24, 2026 High USaisupply chaininfostealer
supply-chain OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat This report details a significant supply chain attack leveraging OpenClaw’s Skill Marketplace, highlighting the emerging threat of AI agentic software. Malicious skills, including infostealers and evasion techniques, wer… Palo Alto Unit 42 · Jun 23, 2026 High USaiagenticsupply chain
malware New macOS ClickFix attack silently mounts DMGs to push infostealer A new macOS ClickFix campaign is using Terminal commands to silently deploy the Atomic macOS Stealer (AMOS) infostealer, targeting users through fake CAPTCHA pages. The malware steals sensitive data like browser credenti… BleepingComputer · Jun 23, 2026 High USmacosclickfixinfostealer
threat-intel A Glimpse into the “Search Your Target” Market for Stolen Credentials This report details a growing underground market where threat actors are offering ‘search your target’ services, leveraging massive collections of stolen credentials. Researchers analyzed 470 forum posts revealing a serv… BleepingComputer · Jun 22, 2026 High UScredential theftinfostealerunderground market
malware Over 400 Arch Linux packages compromised to push rootkit, infostealer Over 400 Arch Linux packages within the AUR repository have been compromised, distributing a Linux rootkit and infostealer malware designed to steal developer credentials and access tokens. The attack involved a maliciou… BleepingComputer · Jun 12, 2026 High USrootkitinfostealeraur
supply-chain New IronWorm malware hits 36 packages in npm supply-chain attack A new supply-chain attack leveraging the IronWorm malware has compromised 36 npm packages, targeting developers and CI environments with infostealer capabilities. The malware utilizes stolen credentials and a sophisticat… BleepingComputer · Jun 4, 2026 High supply chainnpmrust
threat-intel Global Stock Exchange Hit by Monthslong Email Campaign A global stock exchange was targeted by a sophisticated threat actor who gained near-continuous access to a senior executive’s Microsoft Outlook mailbox over a five-month period. The attacker utilized legitimate Windows… Dark Reading · Jun 3, 2026 High UKemail espionagelateral movementdata exfiltration