Threats Tagged 'browser'
View all threats tagged with 'browser'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'browser'
Click on any threat for detailed analysis and mitigation recommendations
On March 19, a researcher on X posted a suspicious Android APK tied to a phishing page impersonating Paidy, a Japanese buy-now-pay-later service. A quick look at the infrastructure behind it revealed an unauthenticated API sitting wide open, with endpoints exposing payloads, command logs, and the C2 source code itself. The server wasn't running a simple credential harvester. Agents for Android, iOS, Windows, Linux, and macOS were present, alongside a canvas-based device fingerprinting system and code that references iOS sandboxing mechanisms by name. The actor behind it is clearly comfortable with Japanese, and large portions of the codebase show signs of LLM-assisted development. Join the discussion | AlienVault OTX General | 04/08/2026, 19:09:00 UTC Added: 04/09/2026, 17:50:46 UTC |
The ToddyCat APT group has developed advanced tools and techniques to covertly access corporate email data by targeting both on-premises Outlook OST files and Microsoft 365 cloud environments. Their toolkit includes PowerShell-based TomBerBil for extracting browser data, TCSectorCopy for copying Outlook OST files, and methods to steal OAuth tokens from Microsoft 365 processes. They leverage SMB for remote file access, dump process memory, and search for access tokens to bypass security monitoring. These tactics enable stealthy data theft of sensitive email content and credentials. Detection guidance is available for each technique to help defenders identify and mitigate these intrusions. The threat is assessed as medium severity due to the complexity and targeted nature of the attacks, with no known exploits in the wild yet. European organizations using Microsoft 365 and Outlook are at risk, especially those with valuable email communications and cloud integrations. Join the discussion | AlienVault OTX General | 11/21/2025, 14:38:00 UTC Added: 11/21/2025, 22:16:22 UTC |
A new information-stealing malware called Gremlin Stealer, written in C#, has been identified by researchers. Advertised on Telegram since March 2025, it targets a wide range of data including browser information, crypto wallets, FTP and VPN credentials. The malware exfiltrates stolen data to a web server for publication. It can bypass Chrome's cookie V20 protection and supports various Chromium and Gecko-based browsers. Gremlin Stealer also targets cryptocurrency wallets, Telegram and Discord sessions, and system information. The stolen data is compressed into a ZIP archive and sent to the attacker's server using a Telegram bot. This evolving threat highlights the need for robust cybersecurity measures to protect against such information stealers. Join the discussion | AlienVault OTX General | 04/29/2025, 16:27:11 UTC Added: 05/29/2025, 16:14:58 UTC |
Showing 1 to 3 of 3 results