MacSync Stealer: A macOS Information Stealer
MacSync Stealer is a macOS-focused information stealer that collects credentials, cookies, SSH keys, AWS credentials, and other sensitive data. It uses ClickFix…
MacSync Stealer is a macOS-focused information stealer that collects credentials, cookies, SSH keys, AWS credentials, and other sensitive data. It uses ClickFix…
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, by correlating endpoint and network…
Cybersecurity researchers have uncovered a new Python-based implant framework called TWINLOOT that abuses trusted Microsoft services for command-and-control (C2) operations. The malware,…
TWINLOOT is a modular Python implant hardened with PyArmor that uses SharePoint Online and Microsoft Teams TURN relays for command-and-control. It steals…
abe_payload.dll is a DLL payload used by the StubMaker stealer to extract credentials from Chromium-based browsers by circumventing app-bound encryption (ABE) protections.
Cybersecurity researchers at CTM360 have exposed a large-scale, global recruitment-themed phishing campaign that leverages Browser-in-the-Browser (BitB) windows to steal Google and Facebook…
PDF Viewer is a malicious browser extension used by Jewelbug that runs on Chrome and Firefox. It requests dangerous permissions to access…
Cybersecurity researchers have uncovered a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that hijacks Chromium web browsers to steal session data and…
The Picus Blue Report 2026, based on over 338 million attack simulations in production environments, reveals a split in enterprise defense effectiveness.…
Two malicious LiteLLM releases on PyPI, versions 1.82.7 and 1.82.8, were live for about 40 minutes on March 24, 2026, carrying credential-stealing…