
Findings and evidence
Cisco Talos documents a cryptocurrency-theft campaign centered on browser-session manipulation and abuse of a legitimate hosted service. The report tracks changes in the campaign’s social-engineering approach and persistence across browser sessions.
Why it matters
Include browser profiles, extension state and relevant session records when the reported fraud has no obvious standalone malware executable. Preserve that material before resetting the browser.
Scope and limits
The legitimate browser extension and hosting platform are not themselves evidence of wrongdoing. Findings require the specific malicious content and its execution context.
Primary source
Cisco Talos: original publication. Source published 2026-09-08. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.