Fake Google Antigravity downloads are stealing accounts in minutes
ID: 1e80a5e5-de1a-5bc0-8017-aa5919e27689
STIX ID: report--1e80a5e5-de1a-5bc0-8017-aa5919e27689
Feed Name: Malwarebytes Blog
A typosquatting campaign distributed a trojanized installer for the popular "Google Antigravity" developer tool that, while installing the legitimate app, executes a PowerShell downloader which can retrieve encrypted .NET payloads. The operation disables AMSI and Defender scans, creates stealthy persistence (an encrypted PNG dropped to ProgramData and a scheduled task that runs a headless conhost/PowerShell), and loads an in-memory info-stealer that harvests browser cookies, saved logins, messaging tokens, FTP credentials and crypto-wallet data; the report includes file hash and network IOCs for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
