logo

The New Face of Phishing: Hackers Weaponize Browser Prompts to Steal Biometric Data

ID: 37b272be-736f-5b8d-a617-1dbb159454c6

STIX ID: report--37b272be-736f-5b8d-a617-1dbb159454c6

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-03-19

Date Updated: 2026-04-23

Author: Ddos

...
...

A highly active social-engineering campaign hosted on edgeone.app lures users with fake verification pages and asks browser permission to access camera, microphone, contacts, and location. Once allowed, JavaScript captures images, audio and video, enumerates device fingerprints, enriches location via external APIs, and exfiltrates files to attackers using the Telegram Bot API. The campaign targets biometric data (face and voice) that are difficult to revoke and can be abused for video-KYC bypass, synthetic identity fraud, deepfakes, and extortion; organizations are advised to audit browser permissions, be skeptical of hardware requests, and report edgeone.app links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.