Visualização normal

Antes de ontemStream principal
  • ✇Cybersecurity News
  • AnonyMousKIT Uses AI Voice Calls to Unlock Stolen iPhones Do Son
    AnonyMousKIT is an AI-powered PhaaS platform that phones iPhone theft victims as fake Apple Support to steal passcodes and beat Activation Lock. Related Posts: Dark Caracal Deploys New GoCaracal Malware Framework Cambodia Malware Campaign Uses PNG Files to Deliver SparkRAT BREEZE COMET Threat Actor Attacks Brazilian Banks The post AnonyMousKIT Uses AI Voice Calls to Unlock Stolen iPhones appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Cisco Talos Discovers JWR Phishing Framework Do Son
    Cisco Talos discovered the JWR phishing framework, a new PhaaS variant. Read our JWR phishing framework analysis to learn about this real-time cyber threat. Related Posts: Jewelbug APT Group Operations Combine Espionage and Fraud US Agencies Warn of AI-Generated Exploits Targeting Siemens S7 PLCs PATCHCORD Malware Hits Afghan Telecom in New APT36 Campaign The post Cisco Talos Discovers JWR Phishing Framework appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Greatness PhaaS Platform Steals Microsoft 365 Tokens Past MFA Do Son
    Researchers expose the Greatness PhaaS platform, an AiTM phishing kit sold on Telegram that steals Microsoft 365 tokens past MFA. Related Posts: SMOKE#SCREEN Campaign Abuses ScreenConnect RMM for Stealthy Remote Access Astaroth WhatsApp Spambot Turns Brazil Victims Into Unwitting Malware Distributors Canadian Man Pleads Guilty to Cloud Hacking Extortion Scheme That Hit 165 Companies The post Greatness PhaaS Platform Steals Microsoft 365 Tokens Past MFA appeared first on Daily CyberSecurity.
     
  • ✇Malwarebytes
  • Infostealers are becoming the go-to phishing payload
    Phishing has changed. Slowly but surely, cybercriminals are turning to infostealers instead. Traditional phishing hasn’t gone away. Far from it. But many attackers are no longer focused solely on tricking victims into entering usernames and passwords on fake login pages. Instead, they are using infostealers to quietly collect passwords, cookies, browser data, and other sensitive information from infected devices. This approach is attractive because it scales well and reduces friction. Inst
     

Infostealers are becoming the go-to phishing payload

3 de Junho de 2026, 05:59

Phishing has changed. Slowly but surely, cybercriminals are turning to infostealers instead.

Traditional phishing hasn’t gone away. Far from it. But many attackers are no longer focused solely on tricking victims into entering usernames and passwords on fake login pages. Instead, they are using infostealers to quietly collect passwords, cookies, browser data, and other sensitive information from infected devices.

This approach is attractive because it scales well and reduces friction. Instead of relying on a victim to type credentials into a fake site, the malware can harvest logins already saved in browsers, session tokens, autofill data, cryptocurrency wallet details, and even files that contain useful information.

This makes the attack chain less visible. A traditional phishing email often leaves obvious clues: a suspicious link, a fake login page, or a strange attachment. Infostealers are different. They can arrive through malicious online ads (malvertising), cracked software, fake browser updates, game cheats, or dubious download sites, and once installed, they work in the background, stealing whatever the victim’s device has in store.

Part of this shift could be due to the widespread adoption of multi-factor authentication (MFA). By stealing session cookies, cybercriminals can bypass MFA, so they can access accounts without needing a password or authentication code.

Another factor is the rise of the malware-as-a-service (MaaS) ecosystem. Infostealers are cheap to deploy, easy to scale, and highly profitable. Rather than building a full attack chain themselves, many criminals buy access to ready-made stealer kits, loaders, or initial access services from underground vendors. This lowers the barrier to entry and allows less-skilled attackers to run credential theft operations.

In many cases, infostealers are just the first stage of a larger criminal operation. The stolen data is collected, packaged, and sold to other criminals interested in the harvested information. These buyers may specialize in fraud, account takeover, business email compromise, or ransomware. A single infected machine can generate multiple revenue streams: credentials for one buyer, session cookies for another, and corporate access or wallet data for a third.

That division of labor is one reason infostealers have become so persistent. Operators can update their code, rotate infrastructure, and launch new campaigns with minimal effort, while affiliates handle distribution through phishing, malvertising, fake downloads, or social media lures.

How to stay safe

Because infostealers commonly arrive through malvertising, fake browser updates, and one-click downloads, it’s worth treating ads and pop-ups with healthy skepticism. My personal tip: Never click on sponsored ads. Instead, visit official websites directly and download software only from trusted sources such as official vendor sites or app stores.

Another increasingly popular technique is ClickFix, a social engineering attack that tricks users into infecting their own devices. Never run commands or scripts copied from websites, emails, or messages unless you trust the source and understand the action’s purpose. If a website tells you to execute a command or perform a technical action, check official documentation or contact support before proceeding.


Picked up something you shouldn’t have?


Pirated software, game cheats, and cracked tools remain some of the most common delivery methods for infostealers. These downloads often come bundled with malware that installs alongside the software you intended to get. The same caution applies to many browser extensions and add-ons that promise extra features or convenience. Stick to extensions from reputable developers, check reviews and permissions carefully, and avoid installing any add-on that asks for more access than it plausibly needs.

Phishing emails are still a major threat, but many can be spotted if you slow down and verify before clicking. Even if an email looks like it comes from a trusted brand, treat unsolicited attachments and links with caution, especially when they urge you to open a file, install something urgently, or fix a billing issue. If you’re unsure, check the sender address, look for typos or odd phrasing, and confirm the request through a separate channel such as the company’s official website rather than the link in the email.


We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

❌
❌