Malwarebytes Labs researchers uncovered multiple campaigns distributing an infostealer we track as NWHStealer, using everything from fake VPN downloads to hardware utilities and gaming mods.
What makes this campaign stand out isn’t just the malware, but how widely and convincingly it’s being spread. Once installed, it can collect browser data, saved passwords, and cryptocurrency wallet information, which attackers may use to access accounts, steal funds, or carry out further attacks. We detected multiple campaigns using different platforms and lures to distribute NWHStealer. The stealer is loaded and executed in several ways, such as self-injection or injection into other processes like RegAsm (Microsoft’s Assembly Registration Tool). Often, additional wrappers such as MSI or Node.js are used as the initial loader.
Read more…
Source: Malwarebytes Labs
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- P&O Ferries data blunder as it sends out passengers’ personal details by text message
August 31, 2026
P&O Ferries was hit by a data breach after mistakenly sending out a full list of passengers’ personal details by text message this morning, we can reveal. A blunder saw the details of 432 passengers travelling on the 12pm P&O ferry from Calais to Dover sent as an attachment in a customer services text message. It is ...
- ValleyRAT masquerading as adware
August 31, 2026
Attackers typically try to pass off malware as legitimate applications or as potentially unwanted programs that users deliberately search for and download, such as cheats or cracks. They often rely on ad and affiliate networks to deliver their creations to victims’ devices. This post examines a less conventional case: a well-known backdoor distributed under the ...
- Healthcare data breach exposes 3.75M patient records
August 30, 2026
Hackers stole medical records, Social Security numbers, government IDs and financial data from millions of CareCloud patients You can be careful with your passwords and still get caught in a breach at a company you may have never heard of. That is one of the frustrating parts of the CareCloud data breach. More than 3.75 million ...
- TerminalFix campaign deploys a reverse tunnel through multistage intrusion
August 28, 2026
Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command. While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply ...
- Australian police arrest alleged TeamPCP masterminds
August 28, 2026
The Australian city of Perth is by some measures the world’s most isolated major metropolis, but is still sufficiently connected to US law enforcement authorities that the FBI was able to help Australia’s Federal Police (AFP) to find two men they believe were the masterminds of TeamPCP, a cybercrime crew that conducted prominent supply chain ...
- Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs
August 27, 2026
Despite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year. While stolen credit cards enable rapid, short-term monetization, Social ...
