infostealer

Hackers poison arrayref Rust crate to push infostealer malware
Hackers compromised the maintainer account for the popular Rust crate `arrayref`, injecting malware that executes during the compilation process on developers' systems. This supply-chain attack also affected two other crates, `append-only-vec` and `internment`, within a short timeframe. The malware, disguised as a dependency, attempts to steal credentials from browsers and establish persistence across various operating systems.

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A campaign involving nearly 800 malicious npm packages has been discovered, delivering a cross-platform Remote Access Trojan (RAT) and infostealer. These packages, some appearing to be AI-generated or typo-squatted, instruct developers to load them via `require()`, leading to the execution of a downloader. This downloader fetches platform-specific payloads from Cloudflare Workers or uses DNS TXT records for delivery, ultimately deploying malware that can interfere with security monitoring and establish persistence.

Armored Likho Hits Government, Energy Sectors With BusySnake Stealer
Cybersecurity researchers have identified a new threat actor, dubbed Armored Likho, targeting government and energy sectors in Russia, Kazakhstan, and Brazil with a sophisticated phishing campaign. The operation utilizes a custom-built Python infostealer named BusySnake, designed to steal credentials, sensitive documents, and other high-value data. The attackers employ AI-generated payloads to obscure their activities and maintain persistence through various methods, including reverse SSH tunneling.

New Malicious Campaign Delivers Vidar Infostealer and Monero Crypto Miner
A new cyberattack campaign is distributing malware that steals user information and mines cryptocurrency. The attackers are using the Vidar infostealer to harvest sensitive data and the XMRig miner to illicitly generate Monero coins.

'BusySnake' Infostealer Slithers Into Critical Infrastructure Networks
A sophisticated information-stealing malware known as 'BusySnake' has been observed targeting critical infrastructure. Threat actors identified as 'Armored Likho' have successfully infiltrated government and electrical power organizations across Russia, Brazil, and Kazakhstan.

Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign
A new phishing campaign has been identified, attributed to a previously unknown APT group named Armored Likho. This group targets government agencies and the electric power sector in Russia, Brazil, and Kazakhstan. They employ a diverse toolkit, including a new Python-based infostealer called BusySnake Stealer, and utilize AI-generated payloads to evade detection and complicate attribution.

Lost in relocation: analysis of a new loader distributing CASTLESTEALER
A new Windows loader, named OXLOADER, has been identified distributing the CASTLESTEALER information-stealing malware. This loader employs sophisticated obfuscation techniques and exploits the Windows .reloc section for shellcode staging. It is being spread through malicious Google Ads that impersonate Node.js, leading victims to fake landing pages. The campaign appears to be financially motivated, with targeting exclusions suggesting a Russian-speaking threat actor.