Vidar Infostealer: Commodity Malware Used by UNC7005
Vidar is a commodity infostealer used by UNC7005 to siphon data from Windows hosts. It is distributed via malicious URLs and phishing…
Vidar is a commodity infostealer used by UNC7005 to siphon data from Windows hosts. It is distributed via malicious URLs and phishing…
Atomic, also known as AMOS, is a commodity infostealer targeting macOS. UNC7005 uses it to steal data from macOS hosts, often delivered…
Atomic Stealer is a known macOS information stealer that collects credentials and sensitive data. AmnesiaStealer shares similar objectives but differentiates itself with…
Remus is a 64-bit variant of the Lumma Stealer malware, distributed via fake websites offering cracked software and pirated games through SEO…
A new campaign has been discovered publishing nearly 800 malicious packages to the npm registry, designed to deliver a cross-platform remote access…
Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in Seattle federal court to computer fraud, wire fraud, aggravated identity theft, and…
UNC5537 is a threat actor tracked by Mandiant, responsible for the 2024 Snowflake customer data breaches. The group exploited stolen credentials from…
Microsoft Threat Intelligence has uncovered a macOS ClickFix operation that uses more than 250 front-end domains to distribute malware, including MacSync and…
ChocoShell, also known as CHERRYPIE, is a PowerShell-based infostealer delivered via ClickFix lures. It steals browser session cookies, saved passwords, Microsoft 365…
Two npm packages in the @joyfill namespace, @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4, have been compromised to deliver a remote access trojan (RAT) associated with…