logo

Fake Software Update Page Delivering Credential-Stealing Malware

ID: 0f8105ac-6fe7-4197-84e9-d2b933006cf9

STIX ID: report--0f8105ac-6fe7-4197-84e9-d2b933006cf9

Threat Score

60/100

Uploaded: 2026-04-13

Created by: Report Uploader

TLP:GREEN
...
...
On 12 April 2026 a marketing user was infected by credential‑stealing malware after being redirected from an ad platform to a spoofed browser update page (https://browser-patch-center.com/update). The site delivered Critical_Browser_Update.zip containing PatchInstaller.exe which established persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run\BrowserPatch, harvested browser credentials, cookies, autofill data and desktop files, staged data in C:\ProgramData\BrowserCache, and exfiltrated over HTTPS to cdn.browser-data-sync.com; the report includes IoCs (URL, archive, executable, registry key, exfil domain, MD5).