Tag: Trojanized Oura MCP

SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer
News

SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer

In order to distribute the information stealer StealC, cybersecurity experts have revealed details of a new SmartLoader campaign that uses a trojanized version of a Model Context Protocol (MCP) server connected to Oura Health. According to a study released with The Hacker News by Straiker's AI Research (STAR) Labs team, the threat actors replicated a genuine Oura MCP Server, a tool that links AI assistants to Oura Ring health data, and constructed a dishonest infrastructure of phony forks and contributors to create credibility. The ultimate goal is to use the Oura MCP server that has been trojanized to distribute the StealC infostealer, which enables the threat actors to obtain login credentials, browser passwords, and cryptocurrency wallet data. Initially identified by OALABS Re...