logo

Latrodectus & ACR Stealer Spread Via Auth Phishing

ID: de2f1014-91bd-5226-ab2d-94037197e856

STIX ID: report--de2f1014-91bd-5226-ab2d-94037197e856

Feed Name: Cyble Blog

Threat Score
72/100

Date Published: 2026-03-18

Date Updated: 2026-07-17

...
...

Cyble Research and Intelligence Labs (CRIL) reports a phishing site (googleaauthenticator.com) posing as Google Safety Centre that tricks users into downloading a signed loader (GoogleAuthSetup.exe) which decrypts and installs Latrodectus (a downloader) and ACR Stealer (an information stealer); the report includes technical analysis, IOCs (file hashes, C2 and config URLs, phishing domain), MITRE ATT&CK mappings, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.