Cybersecurity News
Filters
Filtered by tag: infostealer × Clear
Some Mac users think they're installing OpenAI Codex, but it's actually a malware that can steal passwords in seconds
Matched: cryptocurrency
Cybercriminals are using stolen Google Ads accounts and Google Sites to impersonate OpenAI's Codex download page, targeting macOS users. The fake site avoids detection by hosting malicious content via an iFrame elsewhere. Victims are tricked into pasting Terminal commands, which install AMOS, a macOS infostealer that harvests passwords, browser data, and crypto wallet information. The Windows download button was non-functional — only the Mac payload worked.
MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer
Researchers at Huntress discovered a macOS infostealer called MacSync Stealer being distributed through fake download pages impersonating Claude Code. Users searching for the AI tool were directed to malicious sites that delivered the malware, which steals sensitive data. Huntress SOC analysts reverse engineered the threat and published a full breakdown of its behavior and distribution method.
Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto
Matched: cryptocurrency
Phantom Stealer is a credential-stealing malware that conceals malicious code inside PNG image files to avoid detection. Once executed on Windows systems, it harvests passwords, browser cookies, cryptocurrency wallet data, and other sensitive information. The malware has been used in campaigns targeting users across multiple countries.
