logo

Hackers Leveraging LLM Shared Chats to Steal Your Passwords and Crypto

ID: c4c6a6d8-dbdb-5d6c-adf4-048dfd4306f0

STIX ID: report--c4c6a6d8-dbdb-5d6c-adf4-048dfd4306f0

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-11

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A newly observed campaign abuses sponsored Google search results to push fake ChatGPT/DeepSeek shared chats that contain base64- and custom-encoded commands which, if executed by macOS users, install the multi-stage Shamus info-stealer. The malware uses social-engineered password prompts to escalate privileges, creates a LaunchDaemon for persistence, and exfiltrates browser cookies/passwords, the macOS Keychain, Telegram sessions, VPN profiles, filesystem data, and numerous desktop/hardware cryptocurrency wallets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.