Related Threat Clusters
-
Slovakia Discovers Russian Backdoor in Traffic Speed Cameras
Slovakia's national security service NBU has issued a security alert regarding NERO R-ONE high-speed traffic cameras, which were found to contain a backdoor allowing access via SMS from hardcoded Russian phone numbers.…
4 articles · Updated August 19, 2026 -
ClearFake Campaigns Utilize WordlistLoader to Distribute Amatera Infostealer
A new malware campaign identified as ClearFake employs a loader named WordlistLoader to deploy the Amatera infostealer, targeting Windows users. This loader reconstructs shellcode from encoded English words, enhancing…
6 articles · Updated August 21, 2026 -
Infostealer Malware Hijacks Claude Sessions, Drains User Accounts
Anthropic has alerted users that infostealer malware is compromising Claude accounts by hijacking active login sessions, allowing attackers to deplete usage limits without needing passwords or two-factor authentication.…
32 articles · Updated August 31, 2026 -
ACR Stealer Campaigns Exploit ClickFix and Steganography to Target Enterprises
From late April to mid-June 2026, ACR Stealer, a malware-as-a-service operation, has ramped up its activity targeting enterprise users by stealing browser credentials, session tokens, and sensitive documents. The attack…
10 articles · Updated July 17, 2026 -
InstallFix Campaign Exploits AI Trust to Deliver Malware via Fake Install Pages
The InstallFix campaign targets users by creating fake installation pages for Anthropic's Claude AI, tricking them into executing malware. This sophisticated social engineering tactic exploits the growing reliance on AI…
53 articles · Updated May 5, 2026 -
PavinLoader Malware Exploits ClickFix and Fake Downloads to Deploy Amatera Stealer
PavinLoader, a multi-stage .NET malware loader, is being utilized in ClickFix and fake software download campaigns to deploy the Amatera Stealer. Victims are lured through deceptive pages, such as fake Cloudflare…
2 articles · Updated August 25, 2026 -
New ACRStealer Variant Enhances Evasion Techniques and Threat Level
A newly identified variant of ACRStealer is actively being deployed by HijackLoader, utilizing advanced techniques to evade detection and maximize data theft. This variant employs low-level syscall evasion, AFD-based…
2 articles · Updated March 16, 2026 -
Fake Claude Code Downloads Spread Infostealer Malware Targeting Developers
Cybercriminals are exploiting fake download pages that impersonate Claude Code, a legitimate AI coding assistant, to distribute infostealer malware. Developers and IT professionals are particularly at risk as they may…
22 articles · Updated March 5, 2026 -
EVALUSION and SmartApeSG Campaigns Deploy Amatera Stealer and NetSupport RAT via ClickFix
The EVALUSION and SmartApeSG campaigns are utilizing the ClickFix technique to deploy the Amatera Stealer and NetSupport Remote Access Trojan (RAT). These campaigns target various organizations, exploiting…
3 articles · Updated November 17, 2025 -
EVALUSION and SmartApeSG Campaigns Deploy Amatera Stealer and NetSupport RAT via ClickFix
The EVALUSION and SmartApeSG campaigns utilize the ClickFix technique to deploy the Amatera Stealer and NetSupport RAT. These campaigns target various organizations, leveraging vulnerabilities to execute malicious…
5 articles · Updated November 17, 2025
Recent Intelligence Reports
- Claude hit by infostealer malware campaign stealing session credentials — Finance.Biggo · August 31, 2026
- Breaking: Claude Massive Account Theft Incident — Eu.36Kr · August 31, 2026
- PavinLoader Malware Spreads via ClickFix and Fake Download Campaigns — Technadu · August 25, 2026
- PavinLoader Uses ClickFix and Fake Downloads to Deploy Amatera Stealer via Blockchain C2 — Gbhackers · August 25, 2026
- Hackers Hide Malware Code Inside English Words to Infect Windows Users — Cybersecuritynews · August 20, 2026
- Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras — News.Risky.Biz · August 19, 2026
- ACR Stealer Uses ClickFix, WebDAV, and Steganography to Steal Browser Credentials and Tokens — Gbhackers · July 17, 2026
- InstallFix Uses Fake Claude Code Pages to Deliver Malware | Let's Data Science — Letsdatascience · May 5, 2026