Skip to main content

Threats Tagged 'browser'

View all threats tagged with 'browser'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: browser

Threats Tagged 'browser'

Click on any threat for detailed analysis and mitigation recommendations

On March 19, a researcher on X posted a suspicious Android APK tied to a phishing page impersonating Paidy, a Japanese buy-now-pay-later service. A quick look at the infrastructure behind it revealed an unauthenticated API sitting wide open, with endpoints exposing payloads, command logs, and the C2 source code itself. The server wasn't running a simple credential harvester. Agents for Android, iOS, Windows, Linux, and macOS were present, alongside a canvas-based device fingerprinting system and code that references iOS sandboxing mechanisms by name. The actor behind it is clearly comfortable with Japanese, and large portions of the codebase show signs of LLM-assisted development.

Join the discussion

The ToddyCat APT group has developed advanced tools and techniques to covertly access corporate email data by targeting both on-premises Outlook OST files and Microsoft 365 cloud environments. Their toolkit includes PowerShell-based TomBerBil for extracting browser data, TCSectorCopy for copying Outlook OST files, and methods to steal OAuth tokens from Microsoft 365 processes. They leverage SMB for remote file access, dump process memory, and search for access tokens to bypass security monitoring. These tactics enable stealthy data theft of sensitive email content and credentials. Detection guidance is available for each technique to help defenders identify and mitigate these intrusions. The threat is assessed as medium severity due to the complexity and targeted nature of the attacks, with no known exploits in the wild yet. European organizations using Microsoft 365 and Outlook are at risk, especially those with valuable email communications and cloud integrations.

Join the discussion

A new information-stealing malware called Gremlin Stealer, written in C#, has been identified by researchers. Advertised on Telegram since March 2025, it targets a wide range of data including browser information, crypto wallets, FTP and VPN credentials. The malware exfiltrates stolen data to a web server for publication. It can bypass Chrome's cookie V20 protection and supports various Chromium and Gecko-based browsers. Gremlin Stealer also targets cryptocurrency wallets, Telegram and Discord sessions, and system information. The stolen data is compressed into a ZIP archive and sent to the attacker's server using a Telegram bot. This evolving threat highlights the need for robust cybersecurity measures to protect against such information stealers.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: browser
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses