Samsung TVs stop spying on viewers in Texas. Here’s how to disable ACR anywhere
2026-03-04T22:21:14Z•21eb6b0e3fc63ca99409e9c33ecc6ca1fdb67de436fa793f5b65453ff5cf67bb
API-key-exposureConduentDNS-over-HTTPSGoogle-GeminiSamsung-ACRTeramindValleyRATbrowser-RATcard-skimmingchild-safetycredential-harvestingdata-breachencrypted-DNSfake-websitemalicious-downloadmalwaremonitoring-softwarephishingprivacyregulatory-finessoftware-tamperingsupply-chaintypo-squatting
What happened
Malwarebytes Labs roundup (Feb–Mar 2026) highlights a surge of social-engineering and fake-site campaigns that deliver malware or harvest credentials and payment data. Notable incidents include a tampered FileZilla download that uses encrypted DNS to contact attacker servers, fake vendor/meeting/update pages that install remote-access or commercial monitoring tools (ValleyRAT, Teramind, browser RATs), phishing pages disguised as purchase orders and refund sites harvesting logins and full credit-card data, and a one-letter typo-squatted Huorong site distributing ValleyRAT. The collection also呼s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 21eb6b0e3fc63ca99409e9c33ecc6ca1fdb67de436fa793f5b65453ff5cf67bb
- Enrichment time
- 2026-03-04T22:21:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.