logo

Global Malicious AI Installer Campaign Targets Developer Workstations

ID: a2714339-3eb2-5e74-9e43-b1a82d6770f7

STIX ID: report--a2714339-3eb2-5e74-9e43-b1a82d6770f7

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Ddos

...
...

A sophisticated campaign targets software engineers by publishing typosquatted, SEO-poisoned installer pages that prompt a PowerShell command which concurrently completes a legitimate CLI installation and injects a fileless infostealer into memory; the malware disables AMSI/ETW, performs anti-sandbox checks, harvests credentials and session tokens from browsers and collaboration apps, and communicates with C2 endpoints (e.g., events.msft23.com with /take, /process, /validate) to receive RSA-encrypted tasking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.