New Malware Toolkit Redirects Victims to Malicious Sites Without Changing the URL
ID: 40520a29-bc9f-5aa4-9106-cb98b715fee4
STIX ID: report--40520a29-bc9f-5aa4-9106-cb98b715fee4
Feed Name: GBHackers
Threat Score
The report describes 'Stanley', a purchasable malware toolkit distributed via Russian cybercrime forums and a malicious Chrome Web Store extension (Notely) that overlays fake websites in hidden iframes while keeping the real domain visible to harvest credentials; it includes a web control panel for operators, C2 indicators (api.notely.fun, notely.fun/login, http://api.notely.fun/api, IP 72.61.83.67), and recommends strict extension allowlisting and regular audits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
