Nimbus Manticore uses trojanized coding challenges to deploy NodeRabbit and PollCat RATs across Windows, Linux, and macOS.
Attackers abuse Node.js to execute malicious scripts and deploy payloads in attacks targeting governments, technology ...
Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal ...
Group-IB said its researchers had tracked the Outsider Phishing Kit, operated by a threat actor known as ChenLun, and ...
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...
Malicious Chrome and Edge extensions stole crypto, credentials, sessions, and browser data in a campaign active since early ...
Unlock the full InfoQ experience by logging in! Stay updated with your favorite authors and topics, engage with content, and download exclusive resources. In this episode, Scott Jenson, a veteran UX ...
Every device in my house finally boots to the right dashboard.
For most defenders, a phishing alert ends with a forced password change. Mirage2FA is built to make that response useless.
Chrome and Edge extensions caught delivering cryptocurrency wallet drainers, credential stealers, and session hijacking tools ...
browser extensions were compromised, with malicious updates stealing crypto wallet secrets, passwords, and sensitive user ...