logo

Fake Google Antigravity Installer Can Steal Accounts in Minutes

ID: ff6f199e-43d4-5da5-84e4-94df8f83add2

STIX ID: report--ff6f199e-43d4-5da5-84e4-94df8f83add2

Feed Name: TechRepublic Security

Threat Score
75/100

Date Published: 2026-04-22

Date Updated: 2026-04-23

Author: Kezia Jungco

...
...

A trojanized installer hosted on a typosquatted domain (google-antigravity.com) delivers the legitimate Google Antigravity app while executing a hidden PowerShell step that connects to attacker infrastructure; the second-stage payload can disable Windows protections, persist, and harvest browser cookies, saved credentials, crypto wallets, FTP credentials, and more, enabling near-immediate account takeover and covert remote access, according to Malwarebytes and IBM X-Force.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.