Cyber Security News

New Malware Attacking Magic Enthusiasts to Steal Login Credentials

A sophisticated new malware campaign targeting the magic community has emerged. Dubbed “AbracadabraStealer,” this malware steals login credentials from magic forums, online shops, and streaming platforms where enthusiasts store payment information.

The attackers have crafted a particularly deceptive operation that exploits the trust and specialized interests of magic practitioners and hobbyists around the world.

Threat actors distribute the malware through phishing emails promising exclusive magic trick tutorials or rare footage of legendary performances.

These emails contain malicious PDF attachments or links to compromised websites that appear legitimate but actually host the malware payload.

The attackers have demonstrated detailed knowledge of magic terminology and current trends, making their phishing attempts highly convincing to unsuspecting enthusiasts.

Kaspersky security researchers identified the threat after prominent magicians reported unauthorized account access across multiple platforms.

Their analysis revealed the campaign has been active since early 2025 but remained undetected due to its highly targeted nature and sophisticated obfuscation techniques that allow it to bypass standard security solutions.

Approximately 1,200 individuals across North America, Europe, and Australia have been affected. Victims are predominantly professional magicians, magic shop owners, and dedicated hobbyists active in online communities.

The attackers appear to be specifically targeting individuals with premium accounts or those who have developed proprietary tricks that could have commercial value.

The malware creates a persistent backdoor enabling attackers to harvest browser credentials, monitor keyboard inputs, and capture screenshots during login sessions.

Stolen data is used for fraudulent purchases, unauthorized access to exclusive content, and theft of proprietary magic tricks that later appear for sale on underground forums.

Infection Mechanism

The infection process begins when victims open infected attachments or links.

The malware deploys a JavaScript downloader containing heavily obfuscated code designed to evade detection by security solutions.

The initial payload appears innocuous but contains encoded instructions for retrieving and executing the main malware components.

function d3c0d3(s) {
  return atob(s.replace(/magic/g, "").replace(/illusion/g, "="));
}

const p4yl04d = "magicXm9kdWxlmagicLmV4cG9ydHMgmagicPSBmdW5jdGlvbih=";

let evil_script = d3c0d3(p4yl04d);
eval(evil_script);

This script identifies magic-related software and websites in the browser history before downloading a specialized credential stealer targeting magic community websites.

The malware maintains persistence through a modified registry key disguised as an Adobe update service, ensuring automatic restart with the system and long-term access to the victim’s credentials.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try 50 Request for Free

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago