Agent Tesla Variant Counters Detection With Emoji
New Agent Tesla v4 infostealer uses emoji obfuscation to evade detection and target finance departments.
29 results for “infostealer”
New Agent Tesla v4 infostealer uses emoji obfuscation to evade detection and target finance departments.
OpenSourceMalware finds 16 typosquatted RubyGems, but the real risk is package name reuse and unvalidated author fields.
New macOS infostealer AmnesiaStealer combines credential theft with silent remote browser control, researchers report.
Flashpoint logs 7.4M infostealer infections and 1.7B credentials stolen in H1 2026, up 27%.
Researchers have uncovered a new macOS infostealer that uses ClickFix social engineering and has stealthy remote browser control capabilities.
Device-bound session credentials could curb account takeovers, but rollout is limited for now.
Huntress discovers macOS stealer via ClickFix, targeting crypto wallets and credentials.
A newly identified Go-based malware targets macOS users by leveraging social engineering to steal credentials and crypto assets.
A self-propagating malware campaign has compromised over 1,300 npm packages, leveraging legitimate GitHub workflows to spread.
A malicious version of the Xeno Executor mod is infecting computers with a RAT, granting attackers full control over user devices.
Microsoft identifies a state-sponsored campaign exploiting hotel captive portals to deploy infostealers and harvest credentials.
Security concerns over hijacked packages have forced a temporary freeze on adopting AUR contributions to protect the ecosystem.
A malicious Claude Artifact led users to download a remote access trojan, compromising at least 29 organizations in a recent campaign.
From AI-powered infostealers and automotive vulnerabilities to massive kernel patch requirements, recent threats span multiple sectors.
A sophisticated malware-as-a-service campaign is leveraging social engineering and WebDAV to compromise enterprise environments.
ACR Stealer exploits user-executed commands to siphon session tokens and files, bypassing traditional software vulnerabilities.
A persistent phishing operation is weaponizing fake TrueType font files to distribute infostealers and remote access trojans.
The UAT-11795 threat actor is deploying the Starland RAT via trojanized installers to harvest credentials and crypto assets.
A sophisticated Windows malware framework is compromising cryptocurrency wallets by injecting fake recovery prompts into desktop apps.
A malicious campaign using hundreds of fake repositories is actively deploying the BoryptGrab infostealer to compromised machines.
A new C++ malware strain disguised as an Apple crash reporting tool is targeting local Keychain data and cryptocurrency wallets.
A sophisticated new macOS threat masquerades as system crash reporting tools to siphon credentials through a notarized infection chain.
A malicious npm package injection forced a swift cleanup, highlighting the persistent dangers of compromised build environments.
A sophisticated new C++ information stealer leverages legitimate Apple developer IDs to bypass Gatekeeper and harvest user credentials.
International authorities and private tech firms have dismantled critical infrastructure fueling the Amadey and StealC malware networks.
A newly identified macOS infostealer leverages Apple-notarized installers to bypass system security and harvest sensitive user data.
A decade-long developer's device, infected nearly a year ago, likely provided the gateway for a breach of the Argentine Football Association.
A newly identified infostealer employs unconventional local authentication checks and Rust-based binaries to bypass standard defenses.
A compromised jscrambler package release highlights how modern software pipelines are weaponized to harvest developer secrets.