Criminals are using convincing cryptocurrency wallet screens and browser extensions to steal recovery phrases, login data, and active browser sessions. The activity is linked to a wider CastleLoader campaign that gives attackers several ways to gain access to infected Windows devices. The operation starts with fake software installers and ClickFix-style prompts that pressure victims into running harmful PowerShell commands. Once launched, the loader can retrieve further malware without leaving obvious files behind, making early detection more difficult. Analysts at Arctic Wolf identified the newer payloads while tracking several CastleLoader campaigns, including the Urutyka, Garrigin, and Noidret clusters. The findings...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!