logo

FontPack: A dangerous update

ID: c9b2cec8-1d2d-5391-93c8-e7f2aebfdc1a

STIX ID: report--c9b2cec8-1d2d-5391-93c8-e7f2aebfdc1a

Feed Name: Group-IB Blog

Threat Score
70/100

Date Published: 2021-06-03

Date Updated: 2026-04-27

...
...

Group-IB examined the FontPack malicious landing-page toolkit (aka Domen) which injects JS into compromised or actor-controlled sites to display fake update prompts and deliver payloads; one campaign used it to distribute RedLine stealer (credential and payment-card theft). The report includes script/code analysis, actor and marketplace attribution (multiple seller/user aliases, MagBo links), observed delivery URLs and repositories, malware detonation results identifying RedLine samples, and a table of IOCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.