Intel Drops #3
ID: d8b36185-ae05-5c70-98ee-3e4f7d22c32b
STIX ID: report--d8b36185-ae05-5c70-98ee-3e4f7d22c32b
Feed Name: IntelInsights (Substack)
Threat Score
Threat actors are impersonating a Mexican government SUA site to deliver a malicious JavaScript via drive-by download; once executed, the script runs stealthily (registry changes, headless browser), steals Chrome/Edge session cookies, and beacons to a C2 at `extensioninstaller.onrender.com` for infection confirmation and host ID assignment, with related activity linked to `instalasua.com` as an IoC.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
