Kaspersky reported that information-stealing malware continues to expand across Windows and macOS, with nearly 10 million personal and corporate devices estimated to have been hit in 2023 and the real total likely higher because some operators delay or never publish stolen logs. The company highlighted three active threats: Kral, a stealer delivered exclusively through the Kral downloader via adult-site malvertising and phishing pages; AMOS, a macOS stealer spread through malvertising that impersonates the Homebrew website; and a Vidar campaign that uses YouTube comments to lure users to password-protected archives. Across the cases, the malware targeted browser-stored credentials, session data, and cryptocurrency wallets, creating opportunities for account takeover and financial theft.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Researchers observed a Vidar-based infection chain in which YouTube comments linked users to password-protected archives that ultimately installed Vidar. In the analyzed case, Vidar then downloaded ACR stealer as the exfiltration component, with most victims seen in Brazil.
Kaspersky described an Atomic macOS Stealer campaign in which malvertising led victims to a fake Homebrew website. Victims either downloaded an infected DMG or ran an installation script that installed both the malware and the legitimate Homebrew package.
Kaspersky analyzed Kral as an information stealer delivered through the Kral downloader using adult-site malvertising and phishing pages. The malware targeted browser data and cryptocurrency wallets and used BITS for exfiltration.
Kaspersky Digital Footprint Intelligence estimated that almost 10 million personal and corporate devices were attacked by information stealers in 2023. The company noted the true number may be higher because some operators delay or never publish stolen logs.
Kaspersky released a Securelist report covering the crimeware families FakeSG, Akira, and Atomic macOS Stealer (AMOS). The publication documented these malware threats as part of the company's tracking of information stealers and related crimeware activity.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.