Malicious trading website drops malware that hands your browser to attackers

2026-04-22T20:51:51Z93e3b9cc9a4ce775b5d49fec61cb82a04c95d3d7e4e70599e48dc9c0df0b233c
browser_hijackcredential_theftdata_breachfake_installerinfostealermacOS_spywaremalwarepatch_tuesdayphishingpush_notifications_abuseremote_access/RATsocial_engineeringsupply_chain_trojantrojanzero-day

What happened

Malwarebytes Labs reported a wave of active threats and scams leveraging fake downloads, clone sites, and social engineering to deploy trojans, remote access tools, and infostealers that steal credentials, hijack browsers, and exfiltrate financial and crypto assets. Notable vectors include trojanized installers (Slack, Google Antigravity, fake VPNs and trading‑site lures), email-based RAT/remote‑access drops (DHL and shipment themes), push‑notification clickbait, and targeted phishing (YouTube copyright, booking.com breach-based scams). The feed also highlights macOS spyware claims for an AI‑桌

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
93e3b9cc9a4ce775b5d49fec61cb82a04c95d3d7e4e70599e48dc9c0df0b233c
Enrichment time
2026-04-22T20:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.