logo

New Malware Toolkit Sends Users to Malicious Websites While the URL Stays the Same

ID: b8ac276a-1342-56bf-8f0b-e39c0cef54b5

STIX ID: report--b8ac276a-1342-56bf-8f0b-e39c0cef54b5

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-26

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Stanley is a malware-as-a-service Chrome-extension toolkit discovered in January 2026 that delivers site‑spoofing attacks by injecting a full‑screen iframe over legitimate sites while leaving the address bar unchanged, enabling credential and financial data theft; it is sold on Russian cybercrime forums with options promising publication on the Chrome Web Store, includes a web-based control panel for selecting targets and managing hijack rules, uses IP-based victim identifiers, frequent C2 polling, and backup domain rotation, and has reportedly compromised thousands of users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.