Malware ChocoShell PowerShell Stealer August 1, 2026 ♡Follow0 In-memory PowerShell stealer that collects Microsoft 365 and Azure AD tokens from the Token Broker cache, enabling session replay. Discovered from: Hijacked Hotel Wi-Fi Serves Fake Updates to Deploy CornFlake RAT in CaptiveCrunch Campaign Azure ADChocoShellPowerShelltoken theft