Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. (eclecticiq.com) Financially Motivated Threat Actors Exploit AI Coding Assistants in Large-Scale Infostealer Campaign

(eclecticiq.com) Financially Motivated Threat Actors Exploit AI Coding Assistants in Large-Scale Infostealer Campaign

Scheduled Pinned Locked Moved Uncategorized
cybersecuritythreatintel
1 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • orlysec@swecyb.comO This user is from outside of this forum
    orlysec@swecyb.comO This user is from outside of this forum
    orlysec@swecyb.com
    wrote last edited by
    #1

    (eclecticiq.com) Financially Motivated Threat Actors Exploit AI Coding Assistants in Large-Scale Infostealer Campaign

    Financially motivated threat actors are exploiting AI coding assistant hype in a large-scale infostealer campaign targeting developers via SEO poisoning and typosquatted domains impersonating Gemini CLI, Claude Code, and other tools.

    In brief - eCrime actors use fake AI tool installers to deploy fileless PowerShell infostealers, harvesting credentials, OAuth tokens, and VPN details from enterprise environments. The campaign poses significant supply chain risks, with stolen data enabling initial access to corporate networks.

    Technically - The attack chain begins with SEO-poisoned search results leading to typosquatted domains (e.g., *-setup.com, *-cli.co.com). Victims execute a PowerShell command (irm | iex) that fetches a fileless second-stage payload, disabling ETW and AMSI for evasion. The malware extracts credentials from Windows Credential Manager, browsers (Chrome, Firefox), collaboration tools (Slack, Teams), and remote access apps (WinSCP, OpenVPN). C2 communications use endpoints like /take and /process, with data exfiltrated via encrypted channels. MITRE ATT&CK techniques include T1189 (Drive-by Compromise), T1059.001 (PowerShell), and T1555.003 (Credentials from Web Browsers).

    Source: https://blog.eclecticiq.com/seo-poisoning-campaign-leverages-gemini-and-claude-code-impersonation-to-deliver-infostealer

    #Cybersecurity #ThreatIntel

    1 Reply Last reply
    1
    0
    • R relay@relay.infosec.exchange shared this topic
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Tags
    • Popular
    • World
    • Users
    • Groups