Attackers are abusing interest in Google’s Antigravity AI tool with a typosquatted site, google-antigravity[.]com, that serves a trojanized installer containing the real application plus a hidden PowerShell stage. Researchers said the downloader contacts attacker infrastructure at opus-dsn[.]com, then can deploy follow-on malware that weakens Microsoft Defender, profiles the host, creates persistence with a scheduled task, and loads encrypted .NET payloads in memory. The malware steals browser credentials, cookies, autofill data, messaging and gaming sessions, FTP credentials, and cryptocurrency wallets, while also supporting clipboard hijacking, keylogging, and covert activity on a hidden desktop.
The campaign is particularly dangerous because stolen session cookies can enable rapid account takeover without needing passwords and can sidestep MFA in many cases. Separately, Pillar Security disclosed a now-patched Antigravity vulnerability that allowed prompt injection to trigger sandbox escape and remote code execution through the native find_by_name tool by passing crafted flags to the underlying fd utility before Secure Mode restrictions were enforced. Google patched the flaw on February 28 after responsible disclosure, but the combined reports show Antigravity is being targeted both through malicious lookalike downloads and through weaknesses in agentic tool execution paths.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
Researchers described the fake Antigravity download campaign's second-stage malware, which can weaken Microsoft Defender, establish persistence, steal browser sessions and credentials, target crypto wallets, and enable clipboard hijacking and keylogging.
Attackers used the lookalike domain google-antigravity[.]com to distribute a repackaged Antigravity installer that also launched hidden PowerShell code to contact attacker infrastructure at opus-dsn[.]com.
Pillar Security and CyberScoop publicly disclosed details of the now-patched Antigravity vulnerability, explaining how prompt injection and file-creation features could be chained into sandbox escape and remote code execution.
After fixing the issue, Google awarded Pillar Security a vulnerability reward for the Antigravity finding.
Google fixed the reported Antigravity vulnerability, closing the path that allowed prompt injection to escape sandbox protections and execute code.
Google acknowledged the Antigravity bug on January 7 and accepted the report on January 24 as a valid vulnerability affecting the tool's protections.
Pillar Security reported a prompt-injection vulnerability in Antigravity to Google that could bypass Secure Mode and lead to arbitrary code execution through the native find_by_name tool.
Google's Antigravity tool became available in November 2025, creating the product interest later exploited by both security researchers and threat actors.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcemalwarebytes.com
Open sourcecyberscoop.com
Open sourcepillar.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.