<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[(eclecticiq.com) Financially Motivated Threat Actors Exploit AI Coding Assistants in Large-Scale Infostealer Campaign]]></title><description><![CDATA[<p>(eclecticiq.com) Financially Motivated Threat Actors Exploit AI Coding Assistants in Large-Scale Infostealer Campaign</p><p>Financially motivated threat actors are exploiting AI coding assistant hype in a large-scale infostealer campaign targeting developers via SEO poisoning and typosquatted domains impersonating Gemini CLI, Claude Code, and other tools.</p><p>In brief - eCrime actors use fake AI tool installers to deploy fileless PowerShell infostealers, harvesting credentials, OAuth tokens, and VPN details from enterprise environments. The campaign poses significant supply chain risks, with stolen data enabling initial access to corporate networks.</p><p>Technically - The attack chain begins with SEO-poisoned search results leading to typosquatted domains (e.g., *-setup.com, *-cli.co.com). Victims execute a PowerShell command (irm | iex) that fetches a fileless second-stage payload, disabling ETW and AMSI for evasion. The malware extracts credentials from Windows Credential Manager, browsers (Chrome, Firefox), collaboration tools (Slack, Teams), and remote access apps (WinSCP, OpenVPN). C2 communications use endpoints like /take and /process, with data exfiltrated via encrypted channels. MITRE ATT&amp;CK techniques include T1189 (Drive-by Compromise), T1059.001 (PowerShell), and T1555.003 (Credentials from Web Browsers).</p><p>Source: <a href="https://blog.eclecticiq.com/seo-poisoning-campaign-leverages-gemini-and-claude-code-impersonation-to-deliver-infostealer" rel="nofollow noopener"><span>https://</span><span>blog.eclecticiq.com/seo-poison</span><span>ing-campaign-leverages-gemini-and-claude-code-impersonation-to-deliver-infostealer</span></a></p><p><a href="https://swecyb.com/tags/Cybersecurity" rel="tag">#<span>Cybersecurity</span></a> <a href="https://swecyb.com/tags/ThreatIntel" rel="tag">#<span>ThreatIntel</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/a76539e8-7d53-4abe-9bff-02d7235aaaf8/eclecticiq.com-financially-motivated-threat-actors-exploit-ai-coding-assistants-in-large-scale-infostealer-campaign</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 09:47:29 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/a76539e8-7d53-4abe-9bff-02d7235aaaf8.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 21 May 2026 10:00:31 GMT</pubDate><ttl>60</ttl></channel></rss>