Multiple active social-engineering-driven malware operations are targeting end users through trusted distribution channels. One campaign, dubbed GhostPoster, distributed 17 malicious browser extensions across Chrome, Firefox, and Edge with 840,000+ installs, using legitimate-sounding names (e.g., “Google Translate in Right Click,” “Youtube Download,” “Ads Block Ultimate”) and evading store reviews for years. The extensions used steganography to hide code in PNGs, then extracted payloads to contact attacker infrastructure, enabling credential/data theft, tracking, affiliate-link hijacking, script injection, and HTTP header manipulation to weaken protections.
Separately, threat actors are impersonating Malwarebytes via trojanized ZIP “installers” (e.g., malwarebytes-windows-github-io-X.X.X.zip) and using DLL sideloading—pairing a legitimate EXE with a malicious CoreMessaging.dll—to execute infostealers; reporting highlighted a campaign fingerprint via behash 4acaac53c8340a8c236c91e68244e6cb and distinctive DLL strings used for infrastructure mapping. A different operation identified by CloudSEK involves “RedLineCyber” masquerading as an affiliate of “RedLine Solutions” to build credibility inside private Discord communities and deliver a Python-based clipboard hijacker (often Pro.exe / peeek.exe) aimed at cryptocurrency wallet theft, relying on long-term grooming of high-value targets rather than broad phishing.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Researchers publicly disclosed the fake Malwarebytes campaign, detailing its use of DLL sideloading, behavioral fingerprints, and secondary-stage stealer detections. They said the payloads targeted browser data, cryptocurrency assets, and MFA-related information.
CloudSEK publicly reported that RedLineCyber was impersonating an affiliate of RedLine Solutions to distribute Python-based clipboard hijacker malware through Discord. The malware replaced copied cryptocurrency wallet addresses with attacker-controlled ones and targeted assets including Bitcoin, Ethereum, Solana, Dogecoin, Litecoin, and Tron.
Researchers said the GhostPoster campaign involved 17 malicious browser extensions with more than 840,000 installs across Chrome, Firefox, and Edge. LayerX Security, building on an initial finding by Koi Security, linked the extensions through shared infrastructure and described the activity as a coordinated financially motivated operation.
During analysis of the January 2026 activity, researchers used a behavioral hash, unusual DLL metadata, and benign-looking text files in the archives to pivot to related infrastructure. This connected the operation to additional fake installers themed as Logitech G Hub, OpenIV, and Asus Armoury Crate.
Researchers observed a malware campaign between January 11 and January 15, 2026 that impersonated Malwarebytes installers using ZIP archives named in a malwarebytes-windows-github-io-X.X.X.zip pattern. The archives used DLL sideloading by bundling a legitimate executable with a malicious CoreMessaging.dll to launch infostealer payloads.
CloudSEK's STRIKE team identified a cybercrime actor it calls RedLineCyber in December 2025. The actor was observed infiltrating private Discord communities tied to gaming, gambling, and streaming to socially engineer cryptocurrency users and influencers.
A coordinated malicious extension operation later dubbed GhostPoster was active across the Chrome, Firefox, and Microsoft Edge stores, with some extensions persisting undetected for up to five years. The campaign used legitimate-looking extension names and evasion techniques such as steganography, delayed execution, and runtime-decoded payloads.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.