Fake Google Antigravity Installer Drops NWHStealer — Credential, Session, and Crypto Wallet Theft via Trojanized AI IDE — Threadlinqs Intelligence
As of 2026-05-30, Fake Google Antigravity Installer Drops NWHStealer — Credential, Session, and Crypto Wallet Theft via Trojanized AI IDE is a high-severity malware threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-0405 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: N/A · FINANCIAL
A malvertising and typosquatting campaign distributes a trojanized Google Antigravity installer from google-antigravity[.]com that launches the legitimate AI IDE while a PowerShell-staged .NET stealer
Malwarebytes publicly disclosed on 2026-04-21 that threat actors are distributing a trojanized Windows installer impersonating Google Antigravity — Google's agentic AI coding IDE launched in November 2025. The campaign capitalizes on search intent around the product launch and is seeded through SEO poisoning, paid-search malvertising, and at least one typosquat domain, google-antigravity[.]com (note: the legitimate product lives at antigravity.google). Victims who download Antigravity_v1.22.2.0.exe (SHA-256 61aca585687ec21a182342a40de3eaa12d3fc0d92577456cae0df37c3ed28e99) receive a working copy of the genuine Google Antigravity application packaged alongside malicious PowerShell logic injected into the MSI CustomAction table. The legitimate UI launches to avoid user suspicion while the malicious stage runs in a hidden console.
Execution begins with a PowerShell downloader cradle that writes a randomly-prefixed script (scr5020.ps1 / pss5032.ps1) and contacts opus-dsn[.]com (resolving to 89.124.96.27). The dropper disables the Antimalware Scan Interface by writing AmsiEnable=0 to HKLM\Software\Policies\Microsoft\Windows Script\Settings, adds Microsoft Defender path exclusions for LOCALAPPDATA, and forces a gpupdate to apply the new posture. Second-stage encrypted payloads (secret.png and GGn.xml, and an encrypted blob masqueraded as MicrosoftEdgeUpdate.png) are pulled from BunnyCDN edge captr.b-cdn[.]net. Payloads are decrypted with AES-256-CBC using PBKDF2 with 10,000 iterations, yielding two .NET assemblies: one is persisted via a scheduled task (LOGON trigger, SYSTEM privileges), and the second executes only in memory to resist disk-based forensics.
The in-memory .NET assembly is an NWHStealer variant — the same family Malwarebytes tracked days earlier across fake Proton VPN pages (vpn-proton-setup[.]com, get-proton-vpn[.]com), Sidebar Diagnostics and HardwareVisualizer lookalikes on SourceForge/onworks.net, and gaming mods on GitHub (Lossless-Scaling v3.22). NWHStealer enumerates Chromium-family browsers (Chrome, Edge, Brave, Chromium, Opera, 360, K-Meleon, Chromodo) and Firefox-family browsers for Logins, Cookies, and Autofills; raids more than 25 cryptocurrency wallet folders and registry keys; scrapes Discord, Telegram, Steam, FTP clients, and Authy/2FA tokens; logs keystrokes; hijacks the clipboard (wallet-address swapping); and can spawn a hidden desktop session for hands-on-keyboard remote control. Exfiltration is AES-CBC encrypted over HTTPS to opus-dsn[.]com; a Telegram dead-drop channel (t[.]me/gerj_threuh) serves as a backup resolver for rotating C2.
The campaign is currently untethered from a named actor but aligns with the broader criminal stealer-as-a-service ecosystem that pivoted aggressively toward fake AI-tooling lures in 2026 (Cursor, Windsurf, Claude Code, and now Antigravity). Targets are indiscriminate — any Windows user searching for Antigravity — but the operational impact skews heaviest against developers and security researchers, who tend to have GitHub PATs, cloud SSO cookies, AWS/GCP credentials, npm/PyPI tokens, and VPN session cookies cached in their browsers. Post-theft, the resulting sessions support downstream supply-chain compromise of the victim's code repositories and cloud tenancies. Blocking the three observed C2/delivery hosts at egress, pinning Google Antigravity downloads to antigravity.google, enforcing AMSI via tamper protection, and rotating browser-resident developer secrets for any user exposed to the installer are the immediate defensive priorities.
Target sectors: technology, software-development, financial, cryptocurrency, gaming, education, consumer
Target regions: Global, North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1608, T1189, T1566, T1059, T1204, T1218, T1053, T1547, T1548