Browsing Tag
Infostealers
3 posts
Information-stealing malware that targets passwords, cookies, tokens, browser data, wallets, and enterprise access.
SourTrade Malvertising Makes Browsers Build Malware in Memory
Confiant says the SourTrade malvertising campaign impersonates TradingView, Solana, and Luno, then uses service workers and shared workers to make a victim’s browser assemble a unique Windows malware file in memory. The technique weakens hash-based detection and gives crypto users another reason to avoid sponsored-download paths.
ACR Stealer Turns ClickFix Lures Into Browser-Token Theft
Microsoft says ACR Stealer activity rose across customer environments from late April to mid-June, with campaigns using ClickFix lures, WebDAV, MSHTA, obfuscated PowerShell, and even JPEG-hidden payloads. Security teams should treat infections as token and document-exposure events, not just password resets.
Microsoft’s StealC and Amadey Takedown Hits the Credential-Theft Supply Chain
Microsoft, Europol, and security partners disrupted infrastructure used by StealC and Amadey, two malware-as-a-service tools tied to credential theft, ransomware access, and financial fraud. The operation matters because it targeted the supply chain behind intrusions, not just one malware family.