Malicious sites use JavaScript to build malware in browser memory

2026-07-25T19:23:26Z95d68c434351f28c87b36e5683efdbdbb5490cd6b67a5b65c13023aad17cbc9e
AI‑automated post‑exploitClopDNS hijackingDolphin XFlexPLMHermes AI agentMicrosoft 365PTC WindchillShinyHuntersbrowser‑based payloadscredential stuffingcredential theftdata breachin-memory malwarejavascriptmalicious installermalvertisingmalvertising via search adsphishingransomwaresectopratsextortionslopsquattingsupply‑chain/dep‑squatting

What happened

Multiple active campaigns and breaches observed: a large malvertising operation serves fake Solana/Luno/TradingView pages with malicious JavaScript that assembles malware directly in browser memory; a Bing-adserved fake Claude installer distributes SectopRAT; hotel Wi‑Fi DNS changes are redirecting users to fake Microsoft 365 login pages to steal credentials; Clop ransomware is actively targeting Internet‑exposed PTC Windchill and FlexPLM instances for data theft/extortion; and threat actors are leveraging ShinyHunters breach data for sextortion scams. Separately, attackers are using AI tools/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
95d68c434351f28c87b36e5683efdbdbb5490cd6b67a5b65c13023aad17cbc9e
Enrichment time
2026-07-25T19:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Malicious sites use JavaScript to build malware in browser memory · Baitaphish