HypeAgent Stealer: Multi-Stage Infostealer Hijacking Claude, ChatGPT, and Cursor Sessions

    Date: 09/16/2026

    Severity: High

    Summary

    HypeAgent is a multi-stage infostealer that uses JavaScript, PowerShell, .NET loaders, and PNG steganography to evade detection. It combines scheduled-task persistence, encrypted payloads, reflective loading, AMSI bypassing, and process hollowing to execute its payload. The final stealer targets browser credentials, email accounts, cryptocurrency wallets, and AI service sessions. Its ability to steal AI authentication cookies highlights the growing risk of AI account hijacking, while its embedded configuration supports WebSocket-based C2 communication.

    Indicators of Compromise (IOC) List 

    Domain/URLs

    https://files.catbox.moe/knujwn.png

    IP Address

    209.54.103.173

    Hash

    3878923A2E0B1FDB16A307D4ACB132C2

    406be1fd0f04e621aed5e0f672639b2c

    75298E19A56904144133567C0911CB1E

    B30C530239DCD92186D75EE30A682B10

    D5868901602CF1A008592F1A6C6FE544

    EFB9559AF2BDBA23245B1B51CF2EF4DF

    b2837468fc05666447868fc58c66bcf0

    d4c8277e209000b3066b81bb4c065fa5

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "https://files.catbox.moe/knujwn.png" or url like "https://files.catbox.moe/knujwn.png" or siteurl like "https://files.catbox.moe/knujwn.png"

    Detection Query 2 :

    dstipaddress IN ("209.54.103.173") or srcipaddress IN ("209.54.103.173")

    Detection Query 3 :

    md5hash IN ("B30C530239DCD92186D75EE30A682B10","EFB9559AF2BDBA23245B1B51CF2EF4DF","d4c8277e209000b3066b81bb4c065fa5","b2837468fc05666447868fc58c66bcf0","D5868901602CF1A008592F1A6C6FE544","406be1fd0f04e621aed5e0f672639b2c","75298E19A56904144133567C0911CB1E","3878923A2E0B1FDB16A307D4ACB132C2")

    Reference: 

    https://gurucul.com/blog/hypeagent-stealer-multi-stage-infostealer-hijacking-claude-chatgpt-and-cursor-sessions/     


    Tags

    .NETLoadersSteganographyAMSIcryptocurrencyStealerAIWebSocketMalwareInfostealerPowerShell Attack

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags