logo

AI-Driven Phishing Campaign Uses Browser Permissions to Harvest Sensitive Data

ID: 77aff51c-4369-56f0-a2db-7dd817c2e20e

STIX ID: report--77aff51c-4369-56f0-a2db-7dd817c2e20e

Feed Name: The Cyber Express

Threat Score
72/100

Date Published: 2026-03-17

Date Updated: 2026-05-05

Author: Ashish Khaitan

...
...

A Cyble Research & Intelligence Labs report details an active (since early 2026) AI-driven phishing campaign that uses edgeone.app-hosted pages to socially engineer users into granting browser permissions; malicious JavaScript then captures photos, video, audio, contacts and device fingerprinting data and exfiltrates it via Telegram bot APIs. The campaign leverages techniques like HTML5 canvas capture, the Contacts Picker API, external IP/geolocation enrichment, and signs of AI-assisted code generation, presenting risks including identity theft, KYC bypass, targeted social engineering, and extortion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.