Threats Tagged 'browser hijacking'
View all threats tagged with 'browser hijacking'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'browser hijacking'
Click on any threat for detailed analysis and mitigation recommendations
Two previously undocumented .NET malware components were delivered through a ClickFix infection chain. RemotePanel establishes persistent remote access by masquerading as the Windows Time service, providing operators with PowerShell control, file and process management, screen access, modular HVNC, and fleet management capabilities. It uses a BNB Smart Chain contract to dynamically resolve its active Command and Control server, enabling infrastructure rotation without rebuilding the RAT. BoundSiphon runs primarily from memory, targeting browser credentials and sessions, cryptocurrency wallets, password manager data, and documents, including secrets protected by Chromium App-Bound Encryption. Strong code overlap exists between BoundSiphon and a stealer previously documented by Socket, linking the sample to an earlier stealer codebase. The modular design separates persistent access from data theft, allowing operators to replace infrastructure and individual components while maintaining operational capabilities. Join the discussion | AlienVault OTX General | 09/24/2026, 17:43:48 UTC Added: 09/25/2026, 14:18:03 UTC |
Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users. Join the discussion | AlienVault OTX General | 08/13/2026, 11:29:32 UTC Added: 08/13/2026, 13:26:13 UTC |
Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites. Join the discussion | AlienVault OTX General | 08/13/2026, 11:13:15 UTC Added: 08/13/2026, 13:26:13 UTC |
Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party. Join the discussion | AlienVault OTX General | 08/12/2026, 06:52:44 UTC Added: 08/12/2026, 07:56:32 UTC |
A sophisticated multi-stage infection chain was analyzed following successful containment by MDR SOC operations. Initial access occurred through spear-phishing using a logistics rate confirmation lure, delivering CrySome remote access trojan via multiple stages. The attack chain leveraged living-off-the-land techniques, ICMLuaUtil COM interface for UAC bypass, and in-memory AMSI patching. WinDefCtl, an open-source Defender disruption tool, was deployed to weaken endpoint protections before the final payload. CrySome RAT established persistence through scheduled tasks and provided operators with capabilities including hidden VNC, remote command execution, system reconnaissance, and credential theft targeting Chromium-based browsers. The campaign demonstrated modern threat actors' reliance on publicly available tooling combined with legitimate Windows processes to minimize detection while achieving comprehensive system compromise. Join the discussion | AlienVault OTX General | 07/07/2026, 14:14:56 UTC Added: 07/07/2026, 14:28:23 UTC |
FlutterShell is a macOS backdoor campaign active from December 2025 to March 2026, identified as cluster CL-CRI-1089 under Operation FlutterBridge. The threat actors deliberately misused the Flutter framework to deliver malware through malvertising campaigns on Google and YouTube. The malware employs a two-component architecture: a thin Mach-O launcher and a large Flutter payload dylib. Across three generations, the operators rotated Apple Developer certificates, implemented progressive Dart obfuscation, and renamed bridge commands to evade detection. The backdoor uses a WKWebView to load attacker-controlled JavaScript from C2 servers, implementing a conditional execution model where commands are delivered at runtime via a JavaScript-to-native bridge called flutterInvoke. The primary impact includes Chrome browser hijacking to inject sinterfumesco[.]com as the default search provider and persistent infection through silent Sparkle framework updates. Join the discussion | AlienVault OTX General | 06/19/2026, 00:03:22 UTC Added: 06/19/2026, 08:35:48 UTC |
An investigation into phishing activity targeting users across the Middle East and North Africa uncovered SniperDz, a centralized Push-Notification-as-a-Service and Phishing-as-a-Service platform. The operation uses fraudulent Facebook accounts impersonating politicians, public figures, and trusted organizations to promote fake offers including free mobile internet packages and financial compensation. Victims are redirected through trusted link-aggregation services like Linktree and Linkbio to evade detection. SniperDz provides 80 phishing templates mimicking over 30 global brands across financial services, social media, streaming, and gaming platforms. The infrastructure employs browser notification abuse, history manipulation creating a back-button prison, premium SMS subscriptions, premium-rate calls, investment scams, and affiliate marketing for monetization. Analysis revealed over 900 suspicious domains linked to shared hosting infrastructure and a recurring VAPID public key connecting multiple campai... Join the discussion | AlienVault OTX General | 06/11/2026, 11:49:42 UTC Added: 06/11/2026, 14:32:37 UTC |
A financially-motivated cybercrime cluster designated CL-CRI-1089 has launched Operation FlutterBridge, deploying FlutterShell backdoor malware targeting macOS systems through malvertising. Built with the Flutter framework, FlutterShell masquerades as legitimate applications including podcast players and PDF viewers, delivering adware with full backdoor capabilities such as shell command execution and file system manipulation. The malware uses a WebView-based architecture with JavaScript-to-native bridge, allowing attackers to dynamically modify behavior without recompiling. Distribution occurs through hundreds of Google-verified advertisements controlled by shell companies including AdsParkPro LTD and Advantage Web Marketing LLC. The campaign primarily targets Anglophone and Western European markets. All samples were signed with valid Apple Developer IDs and successfully passed notarization, achieving zero detections on VirusTotal initially. The malware hijacks Google Chrome browsers, redirecting traffic ... Join the discussion | AlienVault OTX General | 06/02/2026, 14:33:49 UTC Added: 06/03/2026, 09:33:37 UTC |
This threat involves three advanced browser hijacking techniques targeting Firefox and Chrome browsers. The first technique modifies browser preference files directly to alter settings such as default search engines and homepage configurations. The second, known as BRAT (Browser Remote Access Tool), remotely simulates key presses to manipulate browser behavior, including opening unwanted tabs and changing search engines. The third exploits a Chromium command line switch to load malicious extensions while disabling browser updates to maintain persistence. These methods enable attackers to control browser behavior stealthily, potentially leading to user tracking, ad fraud, or further malware deployment. Although no known exploits are currently active in the wild, the techniques demonstrate evolving sophistication in browser hijacking. The threat is rated medium severity due to its potential impact on user privacy and browser integrity, combined with moderate exploitation complexity. European organizations relying heavily on Chrome and Firefox browsers should be vigilant, as these browsers are widely used across the continent. Detection and mitigation require enhanced monitoring of browser configuration files, command line parameters, and unusual input simulation activities. Proactive measures are essential to prevent persistent hijacking and maintain browser security integrity. Join the discussion | AlienVault OTX General | 12/10/2025, 19:31:46 UTC Added: 12/11/2025, 09:08:56 UTC |
In late July 2025, an organized APT attack using shortcut files was discovered, attributed to the North Korean Kimsuky group. The attackers distribute decoy zip files containing password-protected documents and a disguised shortcut file. When executed, it connects to a C2 server, downloads encrypted payloads, and performs various malicious activities. These include collecting sensitive information from browsers, cryptocurrency wallets, messaging apps, and system files. The collected data is encrypted and sent to the C2 server, which can issue additional commands for remote execution. The attack employs anti-VM techniques and establishes persistence through registry modifications. It also includes a separate malicious DLL for browser process injection. Join the discussion | AlienVault OTX General | 09/24/2025, 10:38:36 UTC Added: 09/24/2025, 12:02:41 UTC |
Showing 1 to 10 of 10 results