Tech News
← Home  ·  All topics

Infostealer

6 GoKawiil briefs on this topic

Fake LastPass Authenticator GitHub repos spread new Rapuncel infostealer

LastPass and Delphos Labs identified a malware campaign that uses SEO-optimized GitHub repositories impersonating LastPass and at least 39 other companies to distribute a previously unseen infostealer called Rapuncel. Victims searching for tools like LastPass Authenticator are led to fake repos where oversized ZIP files hide a renamed Microsoft debugger that sideloads the malicious payload and a Microsoft-signed kernel driver capable of killing 145 different antivirus and EDR products.

Anthropic force-logs-out Claude users hit by infostealer-based session theft

Anthropic notified affected customers that malware on their own computers had stolen active Claude login sessions, letting attackers rack up unauthorized usage and charges. The company responded by signing out compromised sessions, removing saved payment cards, and refunding the fraudulent charges. Anthropic clarified the breach originated from infostealer malware on users' devices, not from any compromise of its own systems.

Flare research finds nearly half of leaked corporate credentials trace to personal devices

A new practitioner's guide from Flare Research examines how infostealer malware like Vidar, RedLine and Lumma harvest corporate logins, browser cookies and saved credentials from infected machines. The study found that about 46% of stealer logs containing corporate credentials came from likely unmanaged or personal devices, and that exposure of credentials and sessions tied to major SaaS and cloud platforms is climbing roughly 29% each year.

Infostealer Malware Used to Hijack Claude AI Session Tokens

A threat actor deployed multiple infostealer malware strains to harvest session data and gain unauthorized access to an undisclosed number of Anthropic Claude user accounts. The attackers reportedly bypassed login credentials entirely by stealing active session tokens rather than passwords.

Anthropic revokes hijacked Claude sessions stolen by infostealer malware

Anthropic has notified a group of Claude users that infostealer malware on their PCs siphoned off active login sessions, letting attackers access their accounts and burn through usage limits. The company is signing out affected accounts, stripping saved payment details, and refunding charges tied to the unauthorized activity while it continues investigating the source.

New WordlistLoader Malware Hides Amatera Infostealer in Plain Text Files

Researchers have identified a new loader tool called WordlistLoader that disguises malicious code as ordinary text files, such as word lists, to slip past security defenses. It's being used in ClickFix-style attacks—where victims are tricked into manually executing commands—to deploy the Amatera infostealer, a malware family that has been rapidly gaining traction among cybercriminals.