Ninja Browser is a trojanized Chromium-based browser targeting Linux systems. It has been distributed in a large-scale campaign that abused Google-hosted services and legitimate-looking discussion content to make download links appear trustworthy. The campaign dynamically selected payloads by operating system, delivering Ninja Browser to Linux victims and Lumma Stealer to Windows victims. Ninja Browser was configured with persistence capabilities, allowing it to remain active after installation. The activity targeted organizations worldwide.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious, trojanized Chromium-based browser delivered to Linux users; it is described as persistence-enabled.
Malware Newsletter Ninja Browser & Lumma Infostealer
Named malware-related browser component referenced alongside Lumma Infostealer; no further details provided in the newsletter text.
Trojanized Chromium-based browser delivered to Linux systems with persistence enabled, distributed via Google-hosted lures masquerading as software updates.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.