logo

Intel Drops #3

ID: d8b36185-ae05-5c70-98ee-3e4f7d22c32b

STIX ID: report--d8b36185-ae05-5c70-98ee-3e4f7d22c32b

Feed Name: IntelInsights (Substack)

Threat Score
68/100

Date Published: 2025-10-16

Date Updated: 2026-04-19

Author: Vasilis Orlof

...
...

Threat actors are impersonating a Mexican government SUA site to deliver a malicious JavaScript via drive-by download; once executed, the script runs stealthily (registry changes, headless browser), steals Chrome/Edge session cookies, and beacons to a C2 at `extensioninstaller.onrender.com` for infection confirmation and host ID assignment, with related activity linked to `instalasua.com` as an IoC.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.