'Stanley' Toolkit Turns Chrome Into Undetectable Phishing Vector
ID: 4cdc2e68-a566-57a1-b072-33de274ba1c9
STIX ID: report--4cdc2e68-a566-57a1-b072-33de274ba1c9
Feed Name: Dark Reading
Varonis researchers uncovered "Stanley," a malware-as-a-service toolkit sold on a Russian cybercrime forum that builds malicious Chrome extensions (disguised as a note-taking extension) to overlay spoofed login pages in the browser while preserving the legitimate URL, enabling credential theft and evasion of typical protective checks; the toolkit includes a C2 panel, configurable spoofing, and claims of guaranteed Chrome Web Store approval, presenting a significant browser-based threat vector for organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
