Hackers Leveraging LLM Shared Chats to Steal Your Passwords and Crypto
ID: c4c6a6d8-dbdb-5d6c-adf4-048dfd4306f0
STIX ID: report--c4c6a6d8-dbdb-5d6c-adf4-048dfd4306f0
Feed Name: cybersecurityNews.com
A newly observed campaign abuses sponsored Google search results to push fake ChatGPT/DeepSeek shared chats that contain base64- and custom-encoded commands which, if executed by macOS users, install the multi-stage Shamus info-stealer. The malware uses social-engineered password prompts to escalate privileges, creates a LaunchDaemon for persistence, and exfiltrates browser cookies/passwords, the macOS Keychain, Telegram sessions, VPN profiles, filesystem data, and numerous desktop/hardware cryptocurrency wallets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
