Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activityextension-plugin-hijackidentity-impersonation-frauddefense-evasion-method

Social-Engineering Malware Campaigns Targeting End Users via Browser Stores and Fake Installers

Updated 3mo agoFirst seen Jan 19, 20263 sources

Multiple active social-engineering-driven malware operations are targeting end users through trusted distribution channels. One campaign, dubbed GhostPoster, distributed 17 malicious browser extensions across Chrome, Firefox, and Edge with 840,000+ installs, using legitimate-sounding names (e.g., “Google Translate in Right Click,” “Youtube Download,” “Ads Block Ultimate”) and evading store reviews for years. The extensions used steganography to hide code in PNGs, then extracted payloads to contact attacker infrastructure, enabling credential/data theft, tracking, affiliate-link hijacking, script injection, and HTTP header manipulation to weaken protections.

Separately, threat actors are impersonating Malwarebytes via trojanized ZIP “installers” (e.g., malwarebytes-windows-github-io-X.X.X.zip) and using DLL sideloading—pairing a legitimate EXE with a malicious CoreMessaging.dll—to execute infostealers; reporting highlighted a campaign fingerprint via behash 4acaac53c8340a8c236c91e68244e6cb and distinctive DLL strings used for infrastructure mapping. A different operation identified by CloudSEK involves “RedLineCyber” masquerading as an affiliate of “RedLine Solutions” to build credibility inside private Discord communities and deliver a Python-based clipboard hijacker (often Pro.exe / peeek.exe) aimed at cryptocurrency wallet theft, relying on long-term grooming of high-value targets rather than broad phishing.

Share:
Social-Engineering Malware Campaigns Targeting End Users via Browser Stores and Fake Installers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jan 19, 20265mo ago

Researchers disclose fake Malwarebytes DLL sideloading infostealer campaign

Researchers publicly disclosed the fake Malwarebytes campaign, detailing its use of DLL sideloading, behavioral fingerprints, and secondary-stage stealer detections. They said the payloads targeted browser data, cryptocurrency assets, and MFA-related information.

CloudSEK reports RedLineCyber Discord clipper campaign

CloudSEK publicly reported that RedLineCyber was impersonating an affiliate of RedLine Solutions to distribute Python-based clipboard hijacker malware through Discord. The malware replaced copied cryptocurrency wallet addresses with attacker-controlled ones and targeted assets including Bitcoin, Ethereum, Solana, Dogecoin, Litecoin, and Tron.

Researchers report GhostPoster campaign tied to 17 malicious extensions

Researchers said the GhostPoster campaign involved 17 malicious browser extensions with more than 840,000 installs across Chrome, Firefox, and Edge. LayerX Security, building on an initial finding by Koi Security, linked the extensions through shared infrastructure and described the activity as a coordinated financially motivated operation.

Jan 15, 20265mo ago

Researchers link fake Malwarebytes lures to broader fake installer infrastructure

During analysis of the January 2026 activity, researchers used a behavioral hash, unusual DLL metadata, and benign-looking text files in the archives to pivot to related infrastructure. This connected the operation to additional fake installers themed as Logitech G Hub, OpenIV, and Asus Armoury Crate.

Jan 11, 20266mo ago

Fake Malwarebytes installer campaign is observed

Researchers observed a malware campaign between January 11 and January 15, 2026 that impersonated Malwarebytes installers using ZIP archives named in a malwarebytes-windows-github-io-X.X.X.zip pattern. The archives used DLL sideloading by bundling a legitimate executable with a malicious CoreMessaging.dll to launch infostealer payloads.

Dec 1, 20257mo ago

CloudSEK identifies RedLineCyber through HUMINT

CloudSEK's STRIKE team identified a cybercrime actor it calls RedLineCyber in December 2025. The actor was observed infiltrating private Discord communities tied to gaming, gambling, and streaming to socially engineer cryptocurrency users and influencers.

Jan 19, 20215y ago

GhostPoster browser extension campaign begins operating in official stores

A coordinated malicious extension operation later dubbed GhostPoster was active across the Chrome, Firefox, and Microsoft Edge stores, with some extensions persisting undetected for up to five years. The campaign used legitimate-looking extension names and evasion techniques such as steganography, delayed execution, and runtime-decoded payloads.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

18 LINKEDOpen in app
Threat actors
2 linked
Affected products
1 linked
Discord
Organizations
10 linked
Koi SecurityLayerXRedlineLogitechDiscordMalwarebytesVirustotalASUSConnectwiseCloudSEK
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.