Hackers Exploiting Arc Browser Popularity with Malicious Google Search Ads
ID: 64a1349f-063d-5a6b-9593-9bc5aa5a0ab0
STIX ID: report--64a1349f-063d-5a6b-9593-9bc5aa5a0ab0
Feed Name: cybersecurityNews.com
### Executive Summary The article documents an active malvertising campaign that lures users to fake Arc browser installers which unpack a multi-stage malware chain (ArcBrowser.exe → bootstrap.exe → PNG-embedded payload → JRWeb.exe) using MEGA API and paste sites for C2, with multiple file hashes, domains, and a C2 IP provided as IOCs. The behavior and payloads are consistent with an information stealer delivered via social-engineered ads and sideloaded legitimate installers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
