Threat actors are exploiting browser push notifications as a novel vector for fileless, cross-platform phishing attacks using a new command-and-control (C2) platform called Matrix Push C2. This framework leverages social engineering to trick users into granting notification permissions on either malicious or compromised legitimate websites. Once access is granted, attackers send notifications that mimic trusted system or browser alerts, often impersonating brands like Cloudflare, PayPal, or Google Chrome, to lure victims into clicking links that redirect to phishing or malware sites. The entire attack chain operates within the browser, bypassing traditional security controls and requiring no initial malware infection, making it effective across all operating systems.
Matrix Push C2 is marketed as a malware-as-a-service (MaaS) kit, sold via cybercrime forums and Telegram, and provides a dashboard for attackers to manage campaigns, customize notification content, and track victim interactions. Features include analytics on delivery and click rates, victim system details, and the ability to impersonate various brands. The service's fileless nature and cross-platform reach make it a significant threat, as it enables persistent communication with compromised users and circumvents common email-based security defenses. Security researchers warn that this approach could see increased adoption due to its effectiveness and ease of use for cybercriminals.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Security reporting documented that attackers were using browser notifications from malicious or compromised sites to trick users into clicking harmful links, with Matrix Push C2 identified as a key platform enabling the activity. The attacks relied on social engineering and brand impersonation to increase user trust and drive credential theft, malware installation, or data theft.
Threat actors began using Matrix Push C2, a browser-native malware-as-a-service platform, to abuse browser notifications for delivering malicious links in fileless, cross-platform phishing attacks. The service was marketed through crimeware channels with features such as phishing templates, victim tracking, and analytics.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcethehackernews.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.