Five Venezuelans Plead Guilty in US Court to ATM Jackpotting
Five Venezuelan nationals have pleaded guilty in US court for attempting ATM jackpotting attacks, a scheme involving the physical installation of malware on ATMs to force unauthorized cash dispensing. The defendants' efforts to compromise the machines were ultimately unsuccessful, according to court proceedings.
A malicious GitHub repository impersonating Anthropic distributes RevStealer, a Windows information-stealing malware that targets passwords, cryptocurrency wallets, and login credentials while operating stealthily. The campaign exploits social engineering tactics, luring victims with promises of free access to a non-existent "Claude Opus 5" application. RevStealer is designed to execute quietly while harvesting sensitive user data.
Anthropic has disclosed that infostealer malware is being used to compromise Claude user accounts by stealing session cookies, allowing attackers to consume API credits and services at victims' expense. This attack vector demonstrates a broader risk where credential-stealing malware can be leveraged against AI platform accounts beyond traditional web services.
Kaspersky researchers have uncovered a new campaign by Mirage Kitten targeting aviation and financial technology organizations across the Middle East and Africa using previously undocumented malware families. The threat actor is deploying NodeRabbit, a Node.js-based malware, and PollCat, a JavaScript variant, marking an expansion of their known toolset against these critical sectors.