Archive for August 8, 2026

SOCRadar Discovers Infostealer “Kynx” Hunting for Wallets, Games, and AI Tools

Posted in Commentary with tags on August 8, 2026 by itnerd

Following a post by skocherhan on X, the SOCRadar Threat Research Unit (STRU) analyzed Kynx, a Malware-as-a-Service (MaaS) stealer featuring a web panel deeply integrated with the malware’s execution flow. 

Kynx is sold on a tiered subscription model (Free, Plus, Pro, Ultra) through a Turkish gaming forum, and reaches well beyond typical credential theft into crypto wallets, gaming accounts, and AI developer tools like Claude Code, Cursor, GitHub Copilot, and ChatGPT.

What STRU Discovered:

  • AI-assisted development: The developer openly credits Gemini for helping build the malware, including its App-Bound Encryption (ABE) bypass and anti-VM detection.
  • A wide, deliberate target list: 65 cryptocurrency wallet extensions, 16 gaming platforms (Steam, Roblox, Minecraft, Battle.net), 8 AI/developer tools, 9 VPN providers, Discord tokens, and browser-saved credentials and card data.
  • A convincing lure: Kynx masks itself behind a fake system update banner, likely distributed via cracked software or ClickFix-style pages, while it runs anti-sandbox checks before exfiltrating data.
  • Live infrastructure: We traced its C2 to kynxdev[.]xyz, where it uses single-use tokens with a 5-minute validity window and permanent IP bans for invalid requests.


Why it matters: Kynx is a clean example of AI showing up on both sides of the malware economy at once — lowering the bar to build sophisticated stealers, and creating a new class of high-value target in the AI tools developers now trust with code and credentials. IOCs include the C2 domain, SHA256 hashes for the binary, and the staging directory pattern (WinSysHealth-{6 digits}) it drops in %TEMP%.

The full report can be found here

Poison Claude Selling Discounted AI Tokens Built on Fake Accounts and Free Credits

Posted in Commentary with tags on August 8, 2026 by itnerd

Researchers have found online service Poison Claude reselling access to Anthropic’s premium AI models at a significant discount with suspicions that these discounts are coming from fraudulently registered cloud accounts filled with free bonus credits. 

More details here: https://www.okta.com/blog/threat-intelligence/free_tokens_for_sale/

Dave Hayes, VP of Product at cybersecurity company FusionAuth, commented:

“The instinct is for Anthropic to hunt down the fake accounts and shut them off preemptively instead of waiting for the “customer” to contest the charge. You’ll mostly come up empty, because there’s no break-in to find. The account signed up, cleared the check, and spent its credits, exactly what it was authorized to do.

The real exploit is the gap between how little it takes to prove who you are and how much value that unlocks. A thin signup check is all that stands between someone and $100 to $350,000 in credits. The only lever that works is upstream.

Stop tying the credits to the signup, and make releasing the money a separate, deterministic decision sized to what’s at stake. Right now the resale price is the market telling you what that gap is worth: 5 to 15 cents on the dollar.”

There is a rush to do things with AI as quickly as possible. People really need to stop and think about it as not everything is golden when you look at it.