logo

Hackers Exploiting Arc Browser Popularity with Malicious Google Search Ads

ID: 64a1349f-063d-5a6b-9593-9bc5aa5a0ab0

STIX ID: report--64a1349f-063d-5a6b-9593-9bc5aa5a0ab0

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2024-05-28

Date Updated: 2026-04-21

Author: Dhivya

...
...

### Executive Summary The article documents an active malvertising campaign that lures users to fake Arc browser installers which unpack a multi-stage malware chain (ArcBrowser.exe → bootstrap.exe → PNG-embedded payload → JRWeb.exe) using MEGA API and paste sites for C2, with multiple file hashes, domains, and a C2 IP provided as IOCs. The behavior and payloads are consistent with an information stealer delivered via social-engineered ads and sideloaded legitimate installers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.