Samsung TVs stop spying on viewers in Texas. Here’s how to disable ACR anywhere

2026-03-04T22:21:14Z21eb6b0e3fc63ca99409e9c33ecc6ca1fdb67de436fa793f5b65453ff5cf67bb
API-key-exposureConduentDNS-over-HTTPSGoogle-GeminiSamsung-ACRTeramindValleyRATbrowser-RATcard-skimmingchild-safetycredential-harvestingdata-breachencrypted-DNSfake-websitemalicious-downloadmalwaremonitoring-softwarephishingprivacyregulatory-finessoftware-tamperingsupply-chaintypo-squatting

What happened

Malwarebytes Labs roundup (Feb–Mar 2026) highlights a surge of social-engineering and fake-site campaigns that deliver malware or harvest credentials and payment data. Notable incidents include a tampered FileZilla download that uses encrypted DNS to contact attacker servers, fake vendor/meeting/update pages that install remote-access or commercial monitoring tools (ValleyRAT, Teramind, browser RATs), phishing pages disguised as purchase orders and refund sites harvesting logins and full credit-card data, and a one-letter typo-squatted Huorong site distributing ValleyRAT. The collection also呼s

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
21eb6b0e3fc63ca99409e9c33ecc6ca1fdb67de436fa793f5b65453ff5cf67bb
Enrichment time
2026-03-04T22:21:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.