Malicious sites use JavaScript to build malware in browser memory
2026-07-25T19:23:26Z•95d68c434351f28c87b36e5683efdbdbb5490cd6b67a5b65c13023aad17cbc9e
AI‑automated post‑exploitClopDNS hijackingDolphin XFlexPLMHermes AI agentMicrosoft 365PTC WindchillShinyHuntersbrowser‑based payloadscredential stuffingcredential theftdata breachin-memory malwarejavascriptmalicious installermalvertisingmalvertising via search adsphishingransomwaresectopratsextortionslopsquattingsupply‑chain/dep‑squatting
What happened
Multiple active campaigns and breaches observed: a large malvertising operation serves fake Solana/Luno/TradingView pages with malicious JavaScript that assembles malware directly in browser memory; a Bing-adserved fake Claude installer distributes SectopRAT; hotel Wi‑Fi DNS changes are redirecting users to fake Microsoft 365 login pages to steal credentials; Clop ransomware is actively targeting Internet‑exposed PTC Windchill and FlexPLM instances for data theft/extortion; and threat actors are leveraging ShinyHunters breach data for sextortion scams. Separately, attackers are using AI tools/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 95d68c434351f28c87b36e5683efdbdbb5490cd6b67a5b65c13023aad17cbc9e
- Enrichment time
- 2026-07-25T19:23:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.