A week in security (March 23 – March 29)

2026-03-30T08:52:28Zee9837b0f4ff8c7b3f5911792972f552e5ba826910d2adfffbd33ff030bea0d9
advanced-flowbrowser-extension-malwareclickfixdarksworddeepfake-scamsfake-app-storesfcc-router-policyfriendlydealerglasswormidentity-theftinfiniti-stealerios-exploitsmacOS-infostealermalwaremessaging-account-hijackphishingpurehvncpython-nuitkasocial-engineeringsupply-chain-riskvenom-stealervirtual-phone-fraudweek-in-security

What happened

Malwarebytes Labs roundup (week of Mar 23–29, 2026) covering multiple active threats and security trends: criminals renting virtual phones to bypass bank fraud checks; a fake Avast site that installs Venom Stealer; a new macOS infostealer (Infiniti Stealer) using ClickFix and Python/Nuitka with CAPTCHAs; GlassWorm campaign that installs a malicious browser extension for surveillance and supply-chain escalation; FBI/CISA warnings about large-scale social engineering hijacks of Signal and WhatsApp; deepfake-assisted scams and forced-labor video-call fraud; FriendlyDealer fake app stores pushing

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
ee9837b0f4ff8c7b3f5911792972f552e5ba826910d2adfffbd33ff030bea0d9
Enrichment time
2026-03-30T08:52:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.