ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
Huntress researchers have uncovered a new ClickFix-style attack campaign targeting macOS users with a Go-based stealer malware capable of stealing cryptocurrency, browser…
Huntress researchers have uncovered a new ClickFix-style attack campaign targeting macOS users with a Go-based stealer malware capable of stealing cryptocurrency, browser…
A new Russian loader-as-a-service (LaaS) operation named DOUBLECUP is leveraging ClickFix social engineering lures and steganographic PNG images cached in victims' browsers…
DOUBLECUP is a Russian loader-as-a-service (LaaS) operation active since June 2026. It uses ClickFix lures and steganographic PNG images to deliver malware…
North Korean threat actors linked to the Contagious Interview campaign have been observed using steganography in SVG image files to conceal malicious…
ACR Stealer payloads were hidden in JPEG images hosted on ImgBB, an image-hosting service.
A Brazilian banking trojan called Ousaban is targeting Windows users in Spain and Portugal, using phishing PDFs disguised as corrupted files. Discovered…
Ousaban, also known as Javali, is a Brazilian banking trojan targeting Windows users in Spain and Portugal. It uses phishing PDFs with…
Microsoft has removed 119 malicious extensions from the Edge Add-ons store that used steganography to hide malware in image and font files.…
DarkSpectre is a Chinese threat actor linked by Koi Security to the StegoAd campaign. It has been active since at least 2021,…
ShadyPanda is a browser extension malware campaign linked to the DarkSpectre threat actor. It shares techniques with StegoAd, including hiding code in…