Samsung TVs stop spying on viewers in Texas. Here’s how to disable ACR anywhere
2026-03-04T21:17:39Z•003b2e92e702a1444f19030e27953d3be8cfa02c38abcabd70e5a05610687250
DoH/DoTapi-key-exposureautomatic-content-recognitionbrowser-ratcredential-harvestingdata-breachencrypted-dnsfake-updatesiotmalicious-downloadmalwarephishingprivacyregulatory-actionsmart-tvsocial-engineeringteramindthird-party-breachtyposquattingvalleyrat
What happened
Collection of Malwarebytes posts (Feb–Mar 2026) describing widespread scams, malware distribution, and privacy incidents: instructions to disable Samsung ACR after a lawsuit settlement; a typosquatted FileZilla site delivering malware that uses encrypted DNS to contact C2; multiple phishing campaigns (credential-harvesting purchase-order scam, fake refund/Avast page); fake Google/Zoom pages that escalate into browser RATs or silently install legitimate monitoring tools (Teramind); a fake Huorong site delivering ValleyRAT; exposure risk from public Google API keys allowing access to Gemini AI;_
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 003b2e92e702a1444f19030e27953d3be8cfa02c38abcabd70e5a05610687250
- Enrichment time
- 2026-03-04T21:17:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.