New EDDIESTEALER Malware Bypasses Chrome’s App-Bound Encryption to Steal Browser Data
Using the well-known ClickFix social engineering technique, which was started by creating phony CAPTCHA verification sites, a new malware operation is disseminating a brand-new Rust-based information stealer called EDDIESTEALER.
According to an analysis by Jia Yu Chan, a researcher at Elastic Security Labs, this campaign uses fraudulent CAPTCHA verification pages to fool users into running a malicious PowerShell script, which then launches the infostealer and harvests private information like login credentials, browser settings, and cryptocurrency wallet details.
Threat actors start the attack chains by infiltrating trustworthy websites with malicious JavaScript payloads that deliver fake CAPTCHA check pages that ask users to prove you are not [a] robot by following a three-step pro...

