New Malware Campaign Exploits PNGs and Infostealers for Account Hijacking

New Malware Campaign Exploits PNGs and Infostealers for Account Hijacking

First seen 31 Aug 2026, 18:59 UTC Theregister 64.5

Article Content

Browse articles
ThreatCluster

A recent malware campaign utilizes a method called TerminalFix to trick users into executing malicious PowerShell commands, leading to the installation of a reverse tunnel on their machines. This attack method, which is a variant of the ClickFix technique, hides malware within PNG files and exploits social engineering tactics to prompt users to run harmful scripts. Victims of this campaign may include organizations and individuals who unknowingly interact with fake overlays mimicking CAPTCHA verifications. Concurrently, Anthropic has reported that infostealer malware is being used to hijack user accounts for unauthorized access to premium AI services, such as Claude, by stealing session cookies and login credentials. Anthropic has taken steps to secure affected accounts by logging users out and removing saved payment methods. The full scope of the impact and the number of affected users remains unclear, as Microsoft has not disclosed specific details regarding the TerminalFix campaign.

Key Points: • TerminalFix malware exploits PowerShell to create reverse tunnels on infected systems. • Infostealer malware is hijacking user accounts for unauthorized access to AI services. • Anthropic has proactively secured affected accounts by logging users out and removing payment methods.

Timeline

2026-08-31
TerminalFix malware campaign identified
Researchers discovered a new malware campaign using TerminalFix to trick users into executing malicious commands, leading to reverse tunnel installations.
Theregister
2026-08-31
Anthropic addresses account hijacking
Anthropic reported that infostealer malware is being used to hijack user accounts for unauthorized access to Claude services, prompting security measures.
Theregister