A Claude Desktop-themed download flow is being used to deliver SectopRAT, showing how ad-driven redirection and fake installers can turn brand trust into a credential and file theft problem.
A cross-border seizure of Kratos infrastructure shows how phishing-as-a-service survives on scale, redundancy, and the ability to keep identity theft running like a business.
A reported ClickFix-to-VIDAR chain ends in a web injector that can steal cookies, run JavaScript, and alter IBAN details inside live banking sessions.
A small operational mistake on a public host exposed live Microsoft 365 phishing infrastructure, revealing how fragile attacker tradecraft can be when shell history and directory listings are left in plain sight.
A newly named threat group is being tied to phishing, AI-generated loaders, and BusySnake Stealer, a mix that turns one bad click into a broader credential risk.
A reported phishing campaign tied to Armored Likho shows how stolen browser data and covert access tools can turn a simple lure into a long-lived intrusion risk for government and energy organizations.
A Python-based infostealer is being tracked as a focused grab for browser logins, Telegram sessions, screenshots, clipboard data, and crypto material - a reminder that one endpoint can hold many forms of usable trust.
A newly named cluster tied to government and power-sector targeting shows how credential theft, tunneling, and persistence can be fused into one access pipeline.
A fast-moving phishing kit is being watched as it shifts from early testing to live deployment, with Microsoft sign-ins in its sights and proxy-style attacks at the center of the risk.
A malware package tied to a Minecraft modding path and on-chain control logic shows how ordinary-looking software can be turned into a resilient access theft tool.
A tracked infostealer family kept changing shape, and its latest move highlights how browser protections and session theft are locked in a race that defenders cannot afford to lose.
A reported multi-organization campaign shows how adversary-in-the-middle kits are moving past password theft and toward session replay, where a stolen sign-in can outlive the click that triggered it.
A tenant-aware phishing kit tied to Microsoft 365 shows how real-time credential replay and session theft can turn a successful sign-in into an identity breach.
A reported Python-based Windows infostealer combines browser credential theft, cookie harvesting, and Discord webhook exfiltration, showing how ordinary user data can become the fastest path to account takeover.
SolyxImmortal shows how a Windows infostealer can turn saved browser data, live keystrokes, and a commodity webhook into a compact theft pipeline.
A compact infostealer can pack password theft, cookie theft, keylogging, and screen capture into one script-driven workflow, turning everyday browser trust into a high-risk target.
Google has moved Device-Bound Session Credentials to general availability in Chrome for Windows, making off-device session replay harder where the browser, platform, and service all support it.
AI can make phishing faster and cleaner, but the deeper problem is older: once attackers capture a password, session cookie, or token, they can often act like a real user.
VoidStealer is a reminder that browser hardening can still be undercut when malware waits for secrets to appear in memory, where encryption no longer helps.
Infostealer malware on personal devices is less about nuisance and more about identity theft: browser cookies, VPN logins, and cloud tokens can be reused against business systems later.