logo

CapCut Users Under Fire

ID: a157f426-a7a3-550d-927a-b9fac986113c

STIX ID: report--a157f426-a7a3-550d-927a-b9fac986113c

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-11-17

Date Updated: 2026-07-16

...
...

Phishing websites pretending to be CapCut installers are actively distributing multiple info-stealers and loaders: CRIL analysts detail an Offx stealer (Python/PyInstaller) that harvests browser credentials, cookies, screenshots, targeted app data, and desktop files, exfiltrates via Telegram or AnonFiles, and deletes traces; a separate BATLoader campaign drops RedLine and an AMSI-bypass .NET payload. The report provides technical analysis, targeted application/file paths, IOCs (hashes and domains), MITRE mappings, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.