Researchers say credential-stealing campaign used AI to build evasion ‘at every stage’

2026-03-31T14:51:45Z86db4de7ab9fff2fde71dfd4ff283238e338f0c2f77bed742032ae2359ee1e28
AI-obfuscationDarkSwordDeepLoadGoogleHandalaIranian threat actorODNIRedLineTrivycredential-stealerextortioniOS exploitinfostealerpersistencepost-quantum-cryptorobocallssecurity-leadershipsupply-chainthreat-huntingvulnerability-acceleration

What happened

A CyberScoop roundup highlights multiple active and emerging threats: ReliaQuest researchers detail DeepLoad, an AI-assisted credential-stealing campaign that weaponizes AI-generated code for heavy obfuscation, keystroke logging, persistence and re-infection. A Trivy supply-chain compromise is expected to spur a broad extortion wave and impact thousands of downstream victims after attackers published malicious packages. A GitHub leak of DarkSword components risks democratizing powerful iPhone/iOS 18 exploits, while law enforcement activity and attribution updates include an alleged RedLine inf

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
86db4de7ab9fff2fde71dfd4ff283238e338f0c2f77bed742032ae2359ee1e28
Enrichment time
2026-03-31T14:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.