Visualização normal

Antes de ontemStream principal
  • ✇Malwarebytes
  • Infostealers are hijacking Claude accounts at users’ expense
    Anthropic has warned some Claude users that criminals are using information stealers to take over their accounts. Rather than guessing passwords or intercepting two-factor authentication (2FA) codes, the attackers steal the browser sessions that prove a user is already logged in. According to a warning email shared publicly by an affected user, the attackers used common infostealer malware to copy Claude login sessions from victims’ computers. They then used those sessions to access the ac
     

Infostealers are hijacking Claude accounts at users’ expense

1 de Setembro de 2026, 07:08

Anthropic has warned some Claude users that criminals are using information stealers to take over their accounts.

Rather than guessing passwords or intercepting two-factor authentication (2FA) codes, the attackers steal the browser sessions that prove a user is already logged in.

According to a warning email shared publicly by an affected user, the attackers used common infostealer malware to copy Claude login sessions from victims’ computers. They then used those sessions to access the accounts and consume their usage.

Warning from Anthropic

“We recently signed you out of Claude and removed the payment method saved on your account, so you’ll need to log back in and re-add your card. We’re sorry for the disruption. Here’s what happened and what we’ve done about it.

What happened

We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage. Our systems detected this activity on your account, and we’ve therefore removed your card on file and signed out the sessions involved to help block further unauthorized access.

If your usage limits looked like they refilled and then drained while you weren’t using Claude, this was likely the cause.”

The message adds that Anthropic has no reason to believe the malware was “related to Claude, installed through Claude, or related to anything you did with Claude.”  

To sum this up:

  • Cybercriminals are spreading infostealers. How they are doing this and whether they are targeting groups likely to use Claude professionally is unknown.
  • Infostealers can bypass standard credentials and multi-factor authentication (MFA) by stealing active browser sessions and session cookies.
  • Once they are able to take over a Claude account, they can consume the victim’s usage and potentially incur additional charges.
  • Anthropic is signing affected users out of Claude, removing saved payment methods, and refunding charges it identifies as unauthorized.

To better understand this, you should know that paid Claude plans can offer additional “Usage credits.” When a subscriber reaches the plan’s session limit, Claude can allow them to continue using the service through consumption-based billing at standard API rates. The user must enable the feature, configure a monthly spending limit or select unlimited spending, and prepay for credits.

Users can also enable auto-reload, which automatically buys more prepaid credits when the balance falls below a threshold. So, in a session-hijacking scenario, a thief could use up the account’s included allowance and any available Usage credits. If auto-reload is enabled, they could also trigger further purchases.

The criminals’ likely motive is to use paid Claude capacity for free. The account and any exposed data could also be useful for fraud, social engineering, or follow-on attacks.

Stolen Claude capacity could be used to write and refine phishing and scam content, build campaign infrastructure, develop, modify, or obfuscate malware, improve delivery methods, and analyze stolen information. Cybercriminals can use AI to support several parts of an operation, although Claude has safeguards and abuse monitoring, and Anthropic says it has disrupted accounts used for malicious activity.

What to do

Anthropic provided advice for dealing with a possible infostealer infection. After removing the malware, we recommend you install an up-to-date, real-time anti-malware solution to help protect you against new infections.

These steps are good practice when cleaning up after infostealer malware:

  1. Scan any computer you use with Claude for malware and remove any malware before logging back in or changing passwords.
  2. Once the malware has been removed, secure the email account you use for Claude by changing its password, signing out of other devices, and enabling two-factor authentication (2FA).
  3. Change sensitive passwords that were saved in the affected browser, including those for banking, work, and cloud services. Check your card statements if you stored payment details in the browser.
  4. Only after completing these steps should you add your payment method to Claude again if you want your plan to continue renewing.

If you still see your usage changing while Claude is idle, or notice an unrecognized charge after completing these steps, contact usersafety@anthropic.com.


From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

  • ✇Cybersecurity News
  • WeedHack Malware Still Hits Minecraft Gamers via Fake Sites Do Son
    WeedHack malware still targets Minecraft gamers through fake client sites and Minecraft SEO poisoning, McAfee Labs warns. Related Posts: SynkLoader Malware Deploys Multi-Language Attack Tools macOS ClickFix Malware Exploits Polygon C2 Cruciferra Malware Loader Uses ClickFix Lures to Kill EDR The post WeedHack Malware Still Hits Minecraft Gamers via Fake Sites appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • WordlistLoader Delivers Amatera Stealer Through ClearFake Campaigns Do Son
    WordlistLoader malware delivers Amatera Stealer through ClearFake fake-CAPTCHA campaigns, using stealthy evasion to steal browser data. Related Posts: Clop Deploys Custom Web Shell in PTC Windchill Extortion Attacks C2Looper: Rust Backdoor Uses GitHub for C2 Control Manic Android Malware Steals Data Without Active Internet The post WordlistLoader Delivers Amatera Stealer Through ClearFake Campaigns appeared first on Daily CyberSecurity.
     
  • ✇ASEC BLOG
  • July 2026 Infostealer Trend Report ATCP
    Content This report summarizes the distribution channels, number of Infostealers, number of detections, and target companies that were disguised as Infostealers collected during the month of July 2026. It was compiled based on results from AhnLab SEcurity intelligence Center (ASEC)’s automated data collection system, email honeypots, and automated C2 analysis, as well as diagnostic logs […]
     

July 2026 Infostealer Trend Report

Por:ATCP
11 de Agosto de 2026, 12:00
Content This report summarizes the distribution channels, number of Infostealers, number of detections, and target companies that were disguised as Infostealers collected during the month of July 2026. It was compiled based on results from AhnLab SEcurity intelligence Center (ASEC)’s automated data collection system, email honeypots, and automated C2 analysis, as well as diagnostic logs […]
  • ✇Cybersecurity News
  • AmnesiaStealer macOS Infostealer Hacks Apple Devices Do Son
    Jamf Threat Labs has discovered a new AmnesiaStealer macOS infostealer malware. The AmnesiaStealer macOS infostealer steals data and hijacks browsers. Related Posts: GEEKOM Mini PC Driver Downloads Found Bundled With Backdoor Since 2024 Abyssos Modular RAT: Zscaler ThreatLabz Analysis Aeternum Blockchain Botnet Hides C2 Commands in Polygon Smart Contracts The post AmnesiaStealer macOS Infostealer Hacks Apple Devices appeared first on Daily CyberSecurity.
     

Apple Mac Malware Lets Attackers Control Browser Sessions After Infection

17 de Agosto de 2026, 08:24

AmnesiaStealer malware targets macOS with data theft and remote browser-session control, potentially exposing accounts already open on compromised Macs.

The post Apple Mac Malware Lets Attackers Control Browser Sessions After Infection appeared first on TechRepublic.

  • ✇Cybersecurity News
  • macOS ClickFix Campaign Hides Its Lure Behind a Fingerprinting Gate Do Son
    A macOS ClickFix campaign now uses a browser fingerprinting gate to hide AMOS infostealer lures from researchers. See how it works. Related Posts: ChainDrop npm Worm Hits 400+ Packages via Blockchain C2 Fake Zoom Installer Drops Overlord RAT on macOS Fake AI Tools Malware Targets Developers Through GitHub The post macOS ClickFix Campaign Hides Its Lure Behind a Fingerprinting Gate appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Fake AI Tools Malware Targets Developers Through GitHub Do Son
    Fake AI tools malware targets developers in a GitHub infostealer campaign using SmartLoader and blockchain C2. See how it works. Related Posts: macOS ClickFix Campaign Hides Its Lure Behind a Fingerprinting Gate DOUBLECUP: New ClickFix Loader Drops CountLoader and DeviceManager RAT Interlock Ransomware Abuses Volatility3 for Credential Theft The post Fake AI Tools Malware Targets Developers Through GitHub appeared first on Daily CyberSecurity.
     

Fake The Odyssey Downloads Are Hiding Password-Stealing Malware

10 de Agosto de 2026, 11:21

Fake downloads of The Odyssey are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information.

The post Fake The Odyssey Downloads Are Hiding Password-Stealing Malware appeared first on TechRepublic.

  • ✇Cybersecurity News
  • Xeno Roblox Malware Spreads a Java Stealer Through Fake Cheats Do Son
    A fake Xeno cheat spreads Xeno Roblox malware, a Java stealer that grabs accounts and crypto wallets and spies via webcam. Learn how to stay safe. Related Posts: QuickFox Supply Chain Attack Delivers FDMTP Implant to Windows Users XCSSET v40 Malware Targets macOS Developers Through Xcode HostDzire Ransomware Attack Causes Complete Data Loss The post Xeno Roblox Malware Spreads a Java Stealer Through Fake Cheats appeared first on Daily CyberSecurity.
     

New Dolphin X Malware Uses AI Profiler to Rank High-Value Victims

Dolphin X malware targets more than 300 apps and includes an AI Profiler that scores infected Windows PCs to help criminals identify high-value victims quickly.
  • ✇ASEC BLOG
  • June 2026 Infostealer Trend Report ATCP
    Contents This report summarizes the distribution channels, number of Infostealers, number of detections, and information on companies targeted by new Infostealers collected during June 2026. The collected samples were obtained through an automated data collection system, an email honeypot system, and an automated malware C2 analysis system operated by AhnLab SEcurity intelligence Center (ASEC). Purpose […]
     

June 2026 Infostealer Trend Report

Por:ATCP
14 de Julho de 2026, 12:00
Contents This report summarizes the distribution channels, number of Infostealers, number of detections, and information on companies targeted by new Infostealers collected during June 2026. The collected samples were obtained through an automated data collection system, an email honeypot system, and an automated malware C2 analysis system operated by AhnLab SEcurity intelligence Center (ASEC). Purpose […]
  • ✇Security Affairs
  • CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Pierluigi Paganini
    New macOS infostealer CrashStealer uses a signed app to bypass Gatekeeper, steals credentials and wallets, then AES-encrypts stolen data. Jamf Threat Labs first spotted CrashStealer in early May 2026 as a suspicious macOS sample uploaded to VirusTotal. By early July, in-the-wild detections confirmed the malware had moved from development into active deployment. The malware is written in native C++, impersonates Apple’s built-in crash-reporting framework, and encrypts everything it collects b
     

CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper

14 de Julho de 2026, 04:42

New macOS infostealer CrashStealer uses a signed app to bypass Gatekeeper, steals credentials and wallets, then AES-encrypts stolen data.

Jamf Threat Labs first spotted CrashStealer in early May 2026 as a suspicious macOS sample uploaded to VirusTotal. By early July, in-the-wild detections confirmed the malware had moved from development into active deployment. The malware is written in native C++, impersonates Apple’s built-in crash-reporting framework, and encrypts everything it collects before sending it out. Most commodity macOS stealers are thin AppleScript wrappers or lightweight Objective-C tools. This one isn’t.

The initial access arrives through a disk image called “Werkbit Setup,” which contains a single application named Werkbit.app. That app is signed with a valid Apple Developer ID, Emil Grigorov (WWB7JA7AQV), and carries a notarization ticket, meaning it clears Gatekeeper on first launch without any warning.

The domain werkbit[.]io, which serves the installer, was registered in late June 2026, and access to the download is gated behind a meeting PIN so the malicious installer isn’t visible to casual visitors.

“We have since identified the stage that precedes the payload: a signed and Apple-notarized dropper, distributed as a disk image named “Werkbit Setup,” that retrieves the CrashStealer payload from attacker infrastructure and launches it.” reads the report published by Jamf. “Because the dropper carries a valid Developer ID and a stapled notarization ticket, it clears Gatekeeper on first launch, in contrast to the ad-hoc-signed payload it installs.”

When the victim opens Werkbit.app, it queries the GitHub API and fetches a file called sys.cache from a repository at mgothiclove/pkeys. That file contains the curl command the dropper runs next, pulling a shell script from endpoint-api-v1[.]com. The script isn’t written to disk in readable form: it arrives as a series of Base64-encoded blobs decoded at runtime before being piped directly to bash.

“The script downloads the payload disk image over cleartext HTTP from hxxp://endpoint-api-v1[.]com/d/f1b24e/download, retrying up to three times, and saves it as CrashReporter.dmg in /tmp.” continues the report. “It mounts the image without browsing or verification (hdiutil attach -nobrowse -noverify -noautoopen -quiet), copies the first .app bundle it finds into a hidden directory at /tmp/.CrashReporter, then detaches the image and deletes the downloaded .dmg. “

The dropper then strips the payload’s existing signature and re-signs it ad-hoc before launching it from that hidden /tmp path. An application bundle launching from a hidden directory under /private/tmp is an unusual and high-confidence indicator on its own.

The downloaded disk image contains CrashReporter.app, which carries the bundle identifier com.apple.crashreporter and an icon designed to look like Apple’s built-in crash-reporting component. The Info.plist contains the C2 address, 179.43.166.242, hardcoded as an App Transport Security exception, visible in cleartext.

“This is likely a byproduct of the authors’ test setup, as it would let an operator reach the C2 regardless of how the server is configured. The reliable takeaway is for defenders: the C2 address sits in the property list in cleartext.” continues the report. “This ATS exception appears in the earlier samples we identified but not in the more recent ones, which omit it.”

Later samples drop this exception, suggesting the operator has since moved to a properly configured TLS endpoint and no longer needs to relax Apple’s network security policy.

The TCC usage-description strings in Info.plist are also worth reading carefully. The malware requests full disk access under the framing “CrashReporter requires Full Disk Access for system administration,” alongside permissions for Desktop, Documents, Downloads, and removable volumes. These strings pre-populate whatever macOS shows the victim in the permission prompt, and the Desktop, Documents, Downloads description matches exactly where the file-search component later walks.

After launch, the malware shows a native macOS password prompt and validates whatever the user enters by calling dscl, a legitimate Apple directory-service utility, with the -authonly option. It loops until a correct password is supplied, then caches the validated credential in ~/.cache/.sys_auth with permissions set to 600. That password is immediately reused to unlock the login keychain via Apple’s own security command-line tool.

Collection is broad. The malware targets Chromium-based browsers including Chrome, Brave, Edge, Opera, Vivaldi, and others, Firefox credential stores, approximately 80 cryptocurrency wallet browser extensions including MetaMask, Phantom, Coinbase, Trust Wallet, Rabby, and Exodus, and 14 password managers including 1Password, Bitwarden, LastPass, Dashlane, and KeePassXC. It also runs a file searcher across ~/Documents and ~/Downloads that skips executables, disk images, large archive formats, and media files to keep the collected set small and relevant. The login keychain copy and the validated account password end up in the same staging area as everything else.

What distinguishes CrashStealer from most macOS stealers is what happens to the data before it leaves the machine.

“The encryption is authenticated and reasonably modern. Each item is encrypted with AES-256-GCM through Apple’s CommonCrypto, following the standard sequence of creating a cryptor (CCCryptorCreateWithMode), setting an initialization vector (CCCryptorGCMSetIV), encrypting (CCCryptorGCMEncrypt), and finalizing the authentication tag (CCCryptorGCMFinal).” states the report.”The 32-byte key is derived with PBKDF2-HMAC-SHA256 over 10,000 iterations (CCKeyDerivationPBKDF), using a passphrase together with a salt.”

The salt is hardcoded in the sample, labeled panel_salt_v1, and a nearby cleartext development string reads “using fallback salt — set CONFIG_CRYPTO_SALT for production,” confirming the operator intended this to be configurable and shipped a development default. The collected files are then zipped into hidden archives with a .zx_ prefix followed by eight random hex characters under ~/.cache/com.apple.crashreporter/. The stealer removes the staging directories after archiving but leaves the .zx_.zip archives behind, making them a reliable artifact for defenders to hunt for.

CrashStealer persists by copying itself to ~/Library/Caches/com.apple.crashreporter/CrashReporter.app, re-signing the copy ad-hoc, and installing a LaunchAgent at ~/Library/LaunchAgents/com.apple.crashreporter.helper.plist. The label is com.apple.crashreporter.helper, continuing the Apple impersonation into the persistence layer. KeepAlive is set with SuccessfulExit as false, meaning launchd restarts the process whenever it exits with an error, keeping it resident across reboots.

Anti-analysis measures include control-flow flattening applied broadly across functions, runtime decryption of sensitive strings from an encrypted blob in the binary’s __const section, and layered anti-debugging.

“A constructor that runs before main, during dynamic-linker initialization, uses sysctl with a KERN_PROC / P_TRACED query, the standard macOS debugger check, and terminates with exit code 45 if one is attached, before any malicious behavior runs.” states Jamf. “Patching out that first check is not enough on its own: a second check later in application initialization exits the same way.”

The delivery domain also hosts a dark-themed operator panel at endpoint-api-v1[.]com/login labeled “Command Panel,” independently spotted by MalwareHunterTeam.

Additional operator interfaces tied to the same campaign have been identified at cohezo[.]io, cohezo[.]com, and cordinex[.]io. Jamf reported the Developer Team ID to Apple after confirming it was used to distribute the malicious dropper.

“CrashStealer’s delivery chain shows real care: rather than a bare, unsigned lure, the operators front the attack with a signed and notarized dropper that clears Gatekeeper before quietly fetching, re-signing and launching the payload.” concludes the report.”What sets it apart from the commodity stealer crowd is less what it collects than how it is built: client-side AES-GCM encryption of the collected files, and an emphasis on analysis resistance through control-flow flattening, encrypted strings and layered anti-debugging.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, malware)

  • ✇ASEC BLOG
  • Vidar Infostealer Being Spread through Phishing Emails ATCP
    1. Overview First identified in 2018, Vidar operates under a Malware-as-a-Service (MaaS) model and continues to be distributed through various attack cases to this day. AhnLab SEcurity intelligence Center (ASEC) has been monitoring cases of Vidar distribution targeting Korea, and this report summarizes the Vidar distribution cases identified in the first half of 2026.    […]
     

Vidar Infostealer Being Spread through Phishing Emails

Por:ATCP
5 de Julho de 2026, 12:00
1. Overview First identified in 2018, Vidar operates under a Malware-as-a-Service (MaaS) model and continues to be distributed through various attack cases to this day. AhnLab SEcurity intelligence Center (ASEC) has been monitoring cases of Vidar distribution targeting Korea, and this report summarizes the Vidar distribution cases identified in the first half of 2026.    […]

New PamStealer Malware Targets macOS Users via Fake Maccy Clipboard App

The newly spotted PamStealer is spreading through a fake Maccy clipboard app and steal Mac passwords, browser data and clipboard content.

Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks

Operation Endgame disrupts StealC malware infrastructure, seizing millions of stolen credentials and targeting servers used in global cybercrime campaigns.

💾

OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat

Unit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud.

The post OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat appeared first on Unit 42.

❌
❌