That dream job offer from Coca-Cola or Ferrari? It’s a trap for your passwords
2026-04-04T08:51:52Z•573a784a58e711dcfa781373dbf389c8d9c392cce5d490b3461df4cbfd222b06
account-takeoveraxiosbrowser-extensionclickfixcredential-harvestdark sworddarkswordfraud-bypassglassworminfostealeriosjob-scammacosnpmpatchingphishingratremote-access-trojanrouter-security","vpn-audit","ai-misuse"social-engineeringsupply-chainvenom-stealervirtual-phoneswhatsappwindows
What happened
Collection of Malwarebytes posts (Mar–Apr 2026) describing multiple active and emerging threats: targeted job-offer phishing campaigns impersonating Coca‑Cola and Ferrari to harvest Google/Facebook credentials; ongoing WhatsApp-on-Windows campaign seeking persistent access; npm supply‑chain compromise of axios that dropped a RAT; macOS threats including Infiniti Stealer (ClickFix + Python/Nuitka) and fake Avast scans that install Venom Stealer; GlassWorm browser‑extension surveillance; FBI/CISA warnings about large-scale social‑engineering hijacks of Signal/WhatsApp; criminals renting virtual/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 573a784a58e711dcfa781373dbf389c8d9c392cce5d490b3461df4cbfd222b06
- Enrichment time
- 2026-04-04T08:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.