The New Face of Phishing: Hackers Weaponize Browser Prompts to Steal Biometric Data
ID: 37b272be-736f-5b8d-a617-1dbb159454c6
STIX ID: report--37b272be-736f-5b8d-a617-1dbb159454c6
Feed Name: securityonline.info
A highly active social-engineering campaign hosted on edgeone.app lures users with fake verification pages and asks browser permission to access camera, microphone, contacts, and location. Once allowed, JavaScript captures images, audio and video, enumerates device fingerprints, enriches location via external APIs, and exfiltrates files to attackers using the Telegram Bot API. The campaign targets biometric data (face and voice) that are difficult to revoke and can be abused for video-KYC bypass, synthetic identity fraud, deepfakes, and extortion; organizations are advised to audit browser permissions, be skeptical of hardware requests, and report edgeone.app links.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
