Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: infostealer (34 articles)Clear

Lunex stealer abuses vulnerable AMD driver to disable security tools and steal credentials

Ontinue tied the Psychedelic Stealer, spread through compromised Ukrainian websites using ClickFix-style fake Cloudflare verification pages, to a wider malware-as-a-service platform called Lunex. The chain starts with a bogus CAPTCHA that delivers a malicious MSI, which drops LunexLoader. The loader bypasses User Account Control through the CMSTPLUA COM object, then uses a bring-your-own-vulnerable-driver technique against the AMD Radeon Software driver PDFWKRNL.sys, affected by CVE-2023-20598, to escalate and evade defenses before fetching the stealer. Researchers note BYOVD is rarely used as a precursor to an infostealer. The final payload extracts credentials from seven Chromium-based browsers, exfiltrates cryptocurrency wallets, and installs a PowerShell-based browser Native Messaging Host for persistent remote filesystem access.

Check
Block the vulnerable PDFWKRNL.sys driver via Microsoft's blocklist, alert on ClickFix-style CAPTCHA lures, and hunt for rogue browser Native Messaging Hosts.
Affected
Windows users tricked by fake Cloudflare CAPTCHA lures run an MSI that loads a vulnerable AMD driver to disable defenses and steal browser and wallet data.
Fix
Enable the vulnerable driver blocklist, restrict MSI and script execution, block copy-paste run-dialog lures, and monitor for UAC bypass via CMSTPLUA.

PamStealer macOS malware adds server-side decryption and fake crypto wallet lure

Jamf Threat Labs flagged a new version of the PamStealer macOS infostealer that can only be unpacked with the attacker's server. Earlier variants embedded payload key material directly in the JavaScript for Automation dropper, but the latest completes a key exchange with the server before the payload unwraps, so it cannot be recovered from a static sample alone. The lure also changed: where July and August versions impersonated the Maccy, Scoppr, and Nancy Clipboard apps, victims are now drawn to a fake site advertising a non-existent cryptocurrency wallet called Wavel. Clicking Download for macOS retrieves a disk image whose AppleScript opens Script Editor with instructions to run the dropper.

Check
Warn macOS users against installing apps from search-driven download sites, and alert on AppleScript files opening Script Editor and JXA droppers reaching external servers.
Affected
macOS users lured by the fake Wavel crypto wallet site run a JXA dropper that fetches a server-side decrypted stealer payload with layered persistence.
Fix
Restrict installation to trusted sources, monitor for JXA and osascript activity contacting unknown hosts, and educate users on fake wallet and app lures.

Fake LastPass installer loads signed kernel driver that disables antivirus and endpoint defenses

LastPass and Delphos Labs reported a fake LastPass Authenticator installer, hosted on a lookalike GitHub page, that installs a Windows kernel driver to shut off security software before a password stealer runs. The driver, named Alinubx.sys, was signed through Microsoft's hardware-compatibility program, scored zero detections on VirusTotal in August, and was not on Microsoft's blocklist. It carries 145 antivirus and security process names and terminates each from the kernel, below where endpoint tools can see or block it. The installer uses DLL side-loading through a renamed Microsoft debugger, escalates to SYSTEM, and ships in padded 128 to 148 MB archives to evade size-limited scanners.

Check
Warn users to install LastPass Authenticator only from official stores, and hunt endpoints for Alinubx.sys, vsdbg side-loading, and unexpected kernel-mode drivers.
Affected
Windows hosts where a user runs the fake installer get a signed kernel driver that silently kills antivirus and endpoint detection before credential theft.
Fix
Deploy Microsoft's vulnerable driver blocklist, restrict driver loading, block the lookalike GitHub domain, and alert on mass termination of security processes.

REVSTEALER modules disable Windows Update and Defender to hide a crypto miner

Researchers at Elastic documented four persistent programs tied to the REVSTEALER infostealer that stay on a machine even after the stealer deletes itself. One disables Windows Update services and Microsoft Defender, adds Defender exclusions, and kills update and malware-removal tasks before hiding a cryptocurrency miner inside legitimate Windows processes. The malware also bypasses Chrome's app-bound encryption by launching the browser in a debugger to read the decryption key from memory, and steals session cookies to take over accounts without passwords. It spreads through game-cheat lures on hijacked video channels and pirated or fake application installers. Because these modules outlive the stealer, a confirmed infection warrants reimaging rather than cleanup.

Check
Treat any REVSTEALER or infostealer detection as an incident and reimage the machine, since companion modules persist after the stealer removes itself, and watch for disabled Defender and high CPU usage.
Affected
Windows users who run game cheats or pirated and fake software; the modules disable protection, mine cryptocurrency, bypass Chrome's encryption to steal cookies, and persist after the stealer deletes itself.
Fix
Restrict local administrator rights so malware cannot disable Update and Defender, block game-cheat and pirated-software sources, monitor for security-tool tampering and mining activity, and reimage confirmed infections rather than deleting individual files.

AI-enhanced malware turns hacked Windows machines into marketplace inventory

Group-IB detailed BraZetsu, a modular malware framework that turns compromised Windows machines into products sold to other criminals. It uses generative AI to triage stolen data and flag high-value victims for initial-access brokers, and it collects digital certificates, browser histories from several browsers, and financial files while watching users through screenshots. Compromised hosts feed an underground access-as-a-service marketplace where buyers can pay a small deposit to purchase entry into a victim's system and then run their own follow-on payloads. Some samples were fully undetected by antivirus at the time of analysis. It shows attackers using AI to scale the triage and resale of stolen access.

Check
Treat any infostealer infection as a potential gateway that could be resold, respond by fully rebuilding and rotating credentials, and hunt for stealthy data collection, browser theft, and unauthorized remote access.
Affected
Windows users infected by this framework; it harvests certificates, browser data, and financial files, uses AI to rank victims for brokers, and enrolls the machine into a resale marketplace.
Fix
Strengthen endpoint detection and application control, enforce phishing-resistant authentication so stolen credentials are less useful, monitor for stealthy collection and remote access, and rebuild rather than clean machines suspected of infostealer compromise.

Poisoned Rust crate ran malware at build time inside a 245-million-download library

Attackers briefly poisoned arrayref, a foundational Rust crate with about 245 million downloads that sits underneath widely used graphics and blockchain libraries, along with two sibling crates from the same maintainer account. The crate code itself was clean; each added a dependency on a typosquat of a popular package whose build script ran during compilation, pulling and executing an infostealer that grabbed host data and browser credentials. Because the malicious code lived in a build script, simply compiling a project that resolved the crate ran it, with nothing from the library needing to be called. The bad versions were pulled within about ninety minutes, but any build during that window was exposed.

Check
If you build Rust projects, check whether arrayref, internment, or append-only-vec resolved during the exposure window, search the Cargo cache for the malicious files, and pin arrayref to 0.3.9 or earlier.
Affected
Rust developers and CI systems that resolved the poisoned crate versions during the window; the malicious build script ran an infostealer at compile time, taking host information and browser credentials.
Fix
Build with committed lockfiles and the locked flag to avoid pulling fresh malicious versions, enable two-factor authentication on registry accounts, and treat any machine that built during the window as potentially compromised.

Sixteen typosquatted RubyGems packages steal browser logins and crypto wallets

Researchers flagged a typosquatting campaign, tracked as StubMaker, that planted sixteen malicious packages on RubyGems to deliver a Windows information stealer. The packages imitate popular Ruby dependencies with clumsy misspellings, betting that a developer will mistype a name during installation. Once installed, the malware harvests browser credentials, cryptocurrency wallets and seed phrases, and Telegram data from the developer's machine. The campaign's name refers to its trick of faking a build toolchain so a malicious install looks like a routine one. It is the latest reminder that open-source package registries remain an easy delivery route for stealers aimed at developers.

Check
Double-check RubyGems dependency names before installing, watch for clumsy misspellings of popular gems, and scan developer machines and CI for the malicious packages if you use Ruby.
Affected
Ruby developers who mistype or fail to verify gem names during installation; the malicious packages install a Windows stealer that takes browser logins, cryptocurrency wallets and seed phrases, and Telegram data.
Fix
Pin and verify dependency names and sources, use lockfiles, prefer tooling that flags typosquats, rotate credentials and wallets on any machine that installed a bad gem, and keep wallets off dev machines.

AmnesiaStealer hijacks live macOS browser sessions to ride past logins

Jamf detailed a new macOS information stealer, AmnesiaStealer, spread through ClickFix lures that trick users into running a command from a fake download page. Beyond harvesting the login password, keychain, browser data, and cryptocurrency wallets, it includes a module that clones the victim's Chromium browser profile, including its logged-in state, into a hidden browser on the infected Mac and gives the attacker live remote control of it through the browser's debugging protocol. Because the session runs on the victim's own device with their real identifiers, this lets the attacker use authenticated accounts while sidestepping multi-factor authentication. Jamf calls it the first macOS malware to combine profile cloning with live remote browser control.

Check
Warn Mac users never to paste and run commands from a web page or fake download prompt, and treat unexpected browser sessions or new hidden browser processes as a compromise indicator.
Affected
macOS users tricked by ClickFix lures into running the loader; AmnesiaStealer steals credentials and wallets and clones logged-in browser sessions for live remote use, letting attackers bypass multi-factor authentication.
Fix
Block known ClickFix infrastructure, educate users against pasted-command prompts, keep macOS and security tooling current, and monitor for browsers launched in debugging mode and unexpected headless browser activity.

Fake Solidity Pro editor extensions steal crypto wallets and developer keys

Researchers at Yeeth Security flagged malicious Visual Studio Code extensions named Solidity Pro that pose as tools for blockchain developers while stealing wallets and credentials. Early versions quietly fetched an encrypted payload from cloud infrastructure after a delay of up to three days and ran it outside the editor to evade quick checks. Later versions became full information stealers, collecting browser profiles, cryptocurrency wallets and seed phrases, source-control tokens, cloud credentials, API keys, and SSH private keys, then sending them out through a Telegram bot. The extensions were pulled from the Open VSX marketplace, but the project's code repository remained available.

Check
Check developer machines for the Solidity Pro extension and remove it, and rotate wallets, source-control tokens, cloud credentials, API keys, and SSH keys if it was installed.
Affected
Blockchain and other developers who installed a Solidity Pro extension; running with the developer's access, it steals cryptocurrency wallets, seed phrases, and source-control, cloud, and infrastructure credentials, exfiltrating them over Telegram.
Fix
Install editor extensions only from trusted publishers, review what an extension can access, keep wallets off development machines, and monitor developer endpoints for payloads fetched and run outside the editor.

Arch Linux halts package adoptions after infostealer floods the user repository

The Arch Linux project temporarily disabled adoption of packages in its user repository, the AUR, after a wave of malicious takeovers of existing packages. Attackers seized packages through compromised maintainer accounts or by adopting orphaned ones, then shipped a Rust-based infostealer that grabs browser credentials, cryptocurrency wallets, password manager data, cloud and developer secrets, AI service API keys, and SSH keys. It also opens remote command execution over an encrypted Tor channel and spreads to other machines using stolen SSH keys. A researcher tracking the campaign claims more than 200 packages were hit, including some popular ones, though that list is not independently confirmed.

Check
If you use the AUR, review recently installed or updated packages and their maintainers, inspect build files before installing, and rotate SSH keys and secrets if you ran a suspect package.
Affected
Arch Linux users who install from the AUR; a hijacked or adopted package can run a Rust infostealer that harvests developer, cloud, and AI credentials and SSH keys, then self-spreads.
Fix
Read AUR build scripts before installing, prefer well-maintained packages, rotate exposed credentials and SSH keys, watch for outbound Tor connections, and treat orphaned or newly adopted packages with particular caution.