← Back
MalwareThe Register·5 hours ago

Anthropic cracks down on hijacked user accounts mining AI tokens

Commodity malware steals authenticated sessions, letting thieves freeload on victims' paid usage

Read full article at The Register

Related Articles

MalwareThe Register·2 hours ago

Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines

A new wave of ClickFix attacks employs a sophisticated multi-stage infection chain that conceals malware within PNG image files before deploying a custom reverse tunnel to compromised systems. The technique represents an escalation in complexity for ClickFix campaigns, moving beyond simple fake support scams to establish persistent remote access on victim machines.

MalwareCheck Point Research·7 hours ago

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

Check Point Research has analyzed JSCeal, a stealer malware distributed as compiled V8 bytecode and executed through a bundled Node.js runtime, which has been actively targeting cryptocurrency applications since March 2024 under various names including WEEVILPROXY and MeadowLocust. The research demonstrates static deobfuscation techniques for reversing JSCeal's compiled bytecode, providing visibility into the malware's obfuscation mechanisms and operational details.

MalwareThe Hacker News·9 hours ago

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

Silver Fox threat actors are distributing the ValleyRAT backdoor disguised as QN Wallpaper, a legitimate Chinese desktop-wallpaper application, which users often add to antivirus exclusions due to its signed status. By running the malware under this trusted process, attackers can evade detection on systems where users have already whitelisted the application. Kaspersky identified this distribution method as part of the group's campaign to establish backdoor access while bypassing security controls.

MalwareSecurityWeek·9 hours ago

Anthropic Warns Claude Users of Infostealer Malware Infections

Anthropic has detected infostealer malware infections among Claude users and is responding by forcing account logouts and removing stored payment information to prevent unauthorized access to compromised accounts. The company is taking these protective measures to limit potential misuse of affected user accounts while infections are remediated.