Skip to main content
infostealer

infostealer

Search complete. 38 mentions across 24 episodes found for "infostealer".

Sep 18, 2026

Spencer AlessiHOST
17:41
So that's a big area of risk for organizations who do development or even just vibe coding, making sure that those repos are protected and locked down and that you scan those repos for secrets, like super important.
Spencer AlessiHOST
17:55
But then also, this to me, I think we're going to see probably a lot more AI credentials in InfoStealer leaks and logs, because a lot of people are using AI and LLMs and ChatGPT and Codex and VS Code and Claude and all that.
Spencer AlessiHOST
18:12
So if those machines get compromised, you know, potentially being able to steal AI credentials from those machines, personal computers, and then that could potentially lead to, you know, corporate access or access to environments and things like that, just like they have in the past for other credentials, like SaaS apps and stuff.
Spencer AlessiHOST
18:30
So that to me is a big one that's not a surprise, but it's something to be mindful of.
Herman PoppleberryHOST
3:27
Modern attackers would rather deliver a Trojan once to a targeted machine than have a virus spreading wildly and triggering every antivirus engine on the planet.
Herman PoppleberryHOST
3:37
The shift from viruses to trojans and infostealers is the shift from spread as far as possible to get in quietly and monetize.
CornHOST
3:45
So let's talk about what's actually out there across operating systems.
CornHOST
3:50
Daniel asked about variants on every OS.
Herman PoppleberryHOST
8:33
So that's
CornHOST
8:34
the landscape.
CornHOST
8:35
Windows as the big target, macOS infostealers on the rise, Android vulnerable through sideloading, iOS locked down but not immune.
CornHOST
8:44
Now Daniel's bigger question, is malware still a major exploit, or has phishing taken over?
EliHOST
20:08
Well, they warned them their tokens were being stolen.
EliHOST
20:10
Quote, we have recently become aware of a bad actor that is using common InfoStealer malware to steal Claude login sessions from people's computers, then using these login sessions to access Claude accounts and consume their usage.
EliHOST
20:22
The email read, InfoStealers are a type of malware, blah, blah, blah.
EliHOST
20:26
When Anthropic saw suspicious activity, it signed the users out, invalidated existing authorizations, issued some refunds, and warn them that they may have malware.
EliHOST
20:35
The Swartz quad account was reinstated after about two weeks.
speaker_1HOST
47:33
Yeah.
speaker_1HOST
47:33
A threat actor finds an exposed GitHub personal access token or uses an InfoStealer to grab a cloud API key from a developer's hidden config file.
speaker_1HOST
47:42
They use that access to quietly infiltrate an organization's Amazon Web Services or Google Cloud environment.
speaker_0HOST
47:48
So they are inside the corporate cloud.
James WilsonHOST
65:23
When that thing starts, as you said, when it starts encrypting a bunch of files and doing that stuff, cool, catch that.
James WilsonHOST
65:30
But we're talking about InfoStealers here that are looking, feeling, and acting like legitimate JavaScript that's executing, legitimate package installs and scripts, right? It's very difficult to even think about how you would apply the same heuristics and models in an EDR sense.
Paul McCartyGUEST
65:49
even when you do have persistence, when you actually, when you've been unlucky enough to get out of cookie version five or invisible ferret, and you've got persistence on your machine, that process is just a node process.
Paul McCartyGUEST
66:01
It's just a Python process and you're a developer probably.
Chris TarbellHOST
18:51
But I mean, not shocking, but yeah, horrible news.
Chris TarbellHOST
18:55
So Anthropic warns InfoStealer malware is hijacking cloud sessions to drain usage.
Chris TarbellHOST
19:00
So Anthropic is emailing some cloud users that commodity InfoStealers stole already authenticated cloud browser sessions from infected PCs and then relayed those sessions to burn through cloud.
Chris TarbellHOST
19:13
included usage, and in some cases, build credit.
Chris TarbellHOST
19:17
No password or 2FA prompt is required on the relay.
Jerry BellHOST
2:36
Alert on OAuth redirects pointing anywhere but Microsoft.
Jerry BellHOST
2:39
Eight, InfoStealers are lifting session tokens and API keys for the model providers alongside passwords, and those tokens replay so the second factor never applies.
Jerry BellHOST
2:50
Treat a Stealer hit as a reason to revoke AI provider sessions and rotate those keys.
Jerry BellHOST
2:55
9.
speaker_0NARRATOR
2:51
The tactic matters because it shows how simple text obfuscation can bypass keyword-based defenses, forcing organizations to normalize hidden characters and rely on broader detection signals.
speaker_0NARRATOR
3:05
And finally, for today, Security researchers have identified four previously unreported RevStealer-linked modules that remain on infected Windows systems even after the main InfoStealer deletes itself, extending the threat beyond the initial theft of credentials and crypto assets.
speaker_0NARRATOR
3:25
One module disables Windows Update and Microsoft Defender before launching a cryptocurrency miner, while others steal wallet data, hijack clipboard crypto addresses, or turn victims' machines into reverse proxies for attacker traffic.
speaker_0NARRATOR
3:42
The findings matter because the malware can look removed while persistence, defense evasion, and financial abuse continue in the background.
CyrusHOST
6:26
But it's, again, a case of identity theft.
CyrusHOST
6:32
Hudson Rock found InfoStealer linked Microsoft credentials associated with several organizations in the campaign and considers stolen credentials a likelihood.
CyrusHOST
6:40
So again, a different independent organization kind of corroborates that information.
CyrusHOST
6:47
So Azure becomes the place where the attacker enters after obtaining a trusted identity.
Imran ShaikhHOST
2:17
That's according to an email the company sent to affected users last week, which has since been shared publicly on Reddit.
Imran ShaikhHOST
2:24
As reported by Security Week, the AI giant points to customers' own computers rather than any breach at Anthropic, telling affected users that InfoStealer malware had harvested active-clawed login sessions from their own PCs.
Imran ShaikhHOST
2:39
Once inside affected accounts, attackers could burn through usage limits and made unauthorized Claude charges.
Imran ShaikhHOST
2:45
If your usage limits look like they refilled and then drained while you weren't using Claude, this was likely the cause, the email reads.

14 more episodes mention infostealer.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.