AI-Driven Phishing Campaign Uses Browser Permissions to Harvest Sensitive Data
ID: 77aff51c-4369-56f0-a2db-7dd817c2e20e
STIX ID: report--77aff51c-4369-56f0-a2db-7dd817c2e20e
Feed Name: The Cyber Express
A Cyble Research & Intelligence Labs report details an active (since early 2026) AI-driven phishing campaign that uses edgeone.app-hosted pages to socially engineer users into granting browser permissions; malicious JavaScript then captures photos, video, audio, contacts and device fingerprinting data and exfiltrates it via Telegram bot APIs. The campaign leverages techniques like HTML5 canvas capture, the Contacts Picker API, external IP/geolocation enrichment, and signs of AI-assisted code generation, presenting risks including identity theft, KYC bypass, targeted social engineering, and extortion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
