New Malware Toolkit Sends Users to Malicious Websites While the URL Stays the Same
ID: b8ac276a-1342-56bf-8f0b-e39c0cef54b5
STIX ID: report--b8ac276a-1342-56bf-8f0b-e39c0cef54b5
Feed Name: cybersecurityNews.com
Stanley is a malware-as-a-service Chrome-extension toolkit discovered in January 2026 that delivers site‑spoofing attacks by injecting a full‑screen iframe over legitimate sites while leaving the address bar unchanged, enabling credential and financial data theft; it is sold on Russian cybercrime forums with options promising publication on the Chrome Web Store, includes a web-based control panel for selecting targets and managing hijack rules, uses IP-based victim identifiers, frequent C2 polling, and backup domain rotation, and has reportedly compromised thousands of users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
