logo

Fake Google Antigravity downloads are stealing accounts in minutes

ID: 1e80a5e5-de1a-5bc0-8017-aa5919e27689

STIX ID: report--1e80a5e5-de1a-5bc0-8017-aa5919e27689

Feed Name: Malwarebytes Blog

Threat Score
78/100

Date Published: 2026-04-21

Date Updated: 2026-04-28

...
...

A typosquatting campaign distributed a trojanized installer for the popular "Google Antigravity" developer tool that, while installing the legitimate app, executes a PowerShell downloader which can retrieve encrypted .NET payloads. The operation disables AMSI and Defender scans, creates stealthy persistence (an encrypted PNG dropped to ProgramData and a scheduled task that runs a headless conhost/PowerShell), and loads an in-memory info-stealer that harvests browser cookies, saved logins, messaging tokens, FTP credentials and crypto-wallet data; the report includes file hash and network IOCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.