home.social

#clipboard — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #clipboard, aggregated by home.social.

  1. iOS 27’s new paste shortcut kills the copy-and-paste menu

    Copy something, and the iOS 27 paste shortcut now pops up right above your keyboard, ready in a…
    #NewsBeep #News #Mobile #Apple #clipboard #iOS27 #Technology #UK #UnitedKingdom
    newsbeep.com/uk/708613/

  2. iOS 27’s new paste shortcut kills the copy-and-paste menu

    Copy something, and the iOS 27 paste shortcut now pops up right above your keyboard, ready in a…
    #NewsBeep #News #Mobile #Apple #AU #Australia #clipboard #iOS27 #Technology
    newsbeep.com/au/820601/

  3. iOS 27’s new paste shortcut kills the copy-and-paste menu

    Copy something, and the iOS 27 paste shortcut now pops up right above your keyboard, ready in a…
    #NewsBeep #News #Mobile #Apple #AU #Australia #clipboard #iOS27 #Technology
    newsbeep.com/au/820601/

  4. Need to copy an existing HTML table as text, markdown, and/or comma-separated values to the clipboard? Using just HTML and JavaScript?

    Developer advocate, and seasoned tech writer Raymond Camden (Code and Cats) has your back. The post is styled as a tutorial, with ample code samples.

    "Copying HTML Tables as Text, Markdown, and CSV"

    raymondcamden.com/2026/07/20/c

    #programming #html #javascript #markdown #csv #text #clipboard

  5. Need to copy an existing HTML table as text, markdown, and/or comma-separated values to the clipboard? Using just HTML and JavaScript?

    Developer advocate, and seasoned tech writer Raymond Camden (Code and Cats) has your back. The post is styled as a tutorial, with ample code samples.

    "Copying HTML Tables as Text, Markdown, and CSV"

    raymondcamden.com/2026/07/20/c

    #programming #html #javascript #markdown #csv #text #clipboard

  6. Need to copy an existing HTML table as text, markdown, and/or comma-separated values to the clipboard? Using just HTML and JavaScript?

    Developer advocate, and seasoned tech writer Raymond Camden (Code and Cats) has your back. The post is styled as a tutorial, with ample code samples.

    "Copying HTML Tables as Text, Markdown, and CSV"

    raymondcamden.com/2026/07/20/c

    #programming #html #javascript #markdown #csv #text #clipboard

  7. Need to copy an existing HTML table as text, markdown, and/or comma-separated values to the clipboard? Using just HTML and JavaScript?

    Developer advocate, and seasoned tech writer Raymond Camden (Code and Cats) has your back. The post is styled as a tutorial, with ample code samples.

    "Copying HTML Tables as Text, Markdown, and CSV"

    raymondcamden.com/2026/07/20/c

    #programming #html #javascript #markdown #csv #text #clipboard

  8. Need to copy an existing HTML table as text, markdown, and/or comma-separated values to the clipboard? Using just HTML and JavaScript?

    Developer advocate, and seasoned tech writer Raymond Camden (Code and Cats) has your back. The post is styled as a tutorial, with ample code samples.

    "Copying HTML Tables as Text, Markdown, and CSV"

    raymondcamden.com/2026/07/20/c

    #programming #html #javascript #markdown #csv #text #clipboard

  9. UniClipboard is an open-source clipboard sync tool for securely sharing text, images, and files across your devices.

    It uses end-to-end encryption, works on Windows, macOS, Linux, Android, and iOS, and doesn't require a cloud account.

    More details: digitalescapetools.com/tools/t

    #OpenSource #Privacy #Productivity #Clipboard #Windows #Linux #macOS #Android #iOS

  10. UniClipboard is an open-source clipboard sync tool for securely sharing text, images, and files across your devices.

    It uses end-to-end encryption, works on Windows, macOS, Linux, Android, and iOS, and doesn't require a cloud account.

    More details: digitalescapetools.com/tools/t

    #OpenSource #Privacy #Productivity #Clipboard #Windows #Linux #macOS #Android #iOS

  11. UniClipboard is an open-source clipboard sync tool for securely sharing text, images, and files across your devices.

    It uses end-to-end encryption, works on Windows, macOS, Linux, Android, and iOS, and doesn't require a cloud account.

    More details: digitalescapetools.com/tools/t

    #OpenSource #Privacy #Productivity #Clipboard #Windows #Linux #macOS #Android #iOS

  12. UniClipboard is an open-source clipboard sync tool for securely sharing text, images, and files across your devices.

    It uses end-to-end encryption, works on Windows, macOS, Linux, Android, and iOS, and doesn't require a cloud account.

    More details: digitalescapetools.com/tools/t

    #OpenSource #Privacy #Productivity #Clipboard #Windows #Linux #macOS #Android #iOS

  13. UniClipboard is an open-source clipboard sync tool for securely sharing text, images, and files across your devices.

    It uses end-to-end encryption, works on Windows, macOS, Linux, Android, and iOS, and doesn't require a cloud account.

    More details: digitalescapetools.com/tools/t

    #OpenSource #Privacy #Productivity #Clipboard #Windows #Linux #macOS #Android #iOS

  14. Contagious Interview malware in SVG images: DPRK campaign

    A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.

    Pulse ID: 6a5a8ba0229db5a5b2686baa
    Pulse Link: otx.alienvault.com/pulse/6a5a8
    Pulse Author: AlienVault
    Created: 2026-07-17 20:08:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault

  15. Contagious Interview malware in SVG images: DPRK campaign

    A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.

    Pulse ID: 6a5a8ba0229db5a5b2686baa
    Pulse Link: otx.alienvault.com/pulse/6a5a8
    Pulse Author: AlienVault
    Created: 2026-07-17 20:08:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault

  16. Contagious Interview malware in SVG images: DPRK campaign

    A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.

    Pulse ID: 6a5a8ba0229db5a5b2686baa
    Pulse Link: otx.alienvault.com/pulse/6a5a8
    Pulse Author: AlienVault
    Created: 2026-07-17 20:08:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault

  17. Contagious Interview malware in SVG images: DPRK campaign

    A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.

    Pulse ID: 6a5a8ba0229db5a5b2686baa
    Pulse Link: otx.alienvault.com/pulse/6a5a8
    Pulse Author: AlienVault
    Created: 2026-07-17 20:08:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault

  18. Contagious Interview malware in SVG images: DPRK campaign

    A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.

    Pulse ID: 6a5a8ba0229db5a5b2686baa
    Pulse Link: otx.alienvault.com/pulse/6a5a8
    Pulse Author: AlienVault
    Created: 2026-07-17 20:08:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault

  19. Link to Pane: буфер обмена Mac Android через протокол Microsoft (потому что иначе — pain (икра слов)

    Привет, Хабр! Пришло время реверсить протоколы снова. Apple я делал. Google тоже. Угадайте какая компания следующая?

    habr.com/ru/articles/1060248/

    #phone_link #link_to_windows #clipboard #macos #reverse_engineering #microsoft #shareware

  20. Link to Pane: буфер обмена Mac Android через протокол Microsoft (потому что иначе — pain (икра слов)

    Привет, Хабр! Пришло время реверсить протоколы снова. Apple я делал. Google тоже. Угадайте какая компания следующая?

    habr.com/ru/articles/1060248/

    #phone_link #link_to_windows #clipboard #macos #reverse_engineering #microsoft #shareware

  21. Link to Pane: буфер обмена Mac Android через протокол Microsoft (потому что иначе — pain (икра слов)

    Привет, Хабр! Пришло время реверсить протоколы снова. Apple я делал. Google тоже. Угадайте какая компания следующая?

    habr.com/ru/articles/1060248/

    #phone_link #link_to_windows #clipboard #macos #reverse_engineering #microsoft #shareware

  22. PamStealer: a Rust-based macOS infostealer that validates credentials through PAM

    PamStealer is a two-stage macOS infostealer distributed as a compiled AppleScript impersonating Maccy, a legitimate clipboard manager, hosted on a fake domain. The first stage uses JavaScript for Automation with Objective-C APIs to download payloads while avoiding shell commands. The second stage is a Rust-based Mach-O binary that validates stolen credentials through PAM before harvesting, reads browser databases directly using bundled SQLite, captures clipboard contents repeatedly via pbpaste, and exfiltrates encrypted data using ChaCha20-Poly1305. It establishes persistence through both modern and legacy login item APIs, masquerades as Finder or System Settings, and tricks victims into granting Full Disk Access through counterfeit alerts. The stealer contacts Ethereum RPC endpoints and employs region-based exclusions targeting Apple silicon systems while avoiding Commonwealth of Independent States countries.

    Pulse ID: 6a471de6cf9848f2ef9503c0
    Pulse Link: otx.alienvault.com/pulse/6a471
    Pulse Author: AlienVault
    Created: 2026-07-03 02:26:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #ChaCha20 #Clipboard #CyberSecurity #Endpoint #InfoSec #InfoStealer #Java #JavaScript #Mac #MacOS #OTX #OpenThreatExchange #RAT #RPC #Rust #SQL #bot #AlienVault

  23. PamStealer: a Rust-based macOS infostealer that validates credentials through PAM

    PamStealer is a two-stage macOS infostealer distributed as a compiled AppleScript impersonating Maccy, a legitimate clipboard manager, hosted on a fake domain. The first stage uses JavaScript for Automation with Objective-C APIs to download payloads while avoiding shell commands. The second stage is a Rust-based Mach-O binary that validates stolen credentials through PAM before harvesting, reads browser databases directly using bundled SQLite, captures clipboard contents repeatedly via pbpaste, and exfiltrates encrypted data using ChaCha20-Poly1305. It establishes persistence through both modern and legacy login item APIs, masquerades as Finder or System Settings, and tricks victims into granting Full Disk Access through counterfeit alerts. The stealer contacts Ethereum RPC endpoints and employs region-based exclusions targeting Apple silicon systems while avoiding Commonwealth of Independent States countries.

    Pulse ID: 6a471de6cf9848f2ef9503c0
    Pulse Link: otx.alienvault.com/pulse/6a471
    Pulse Author: AlienVault
    Created: 2026-07-03 02:26:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #ChaCha20 #Clipboard #CyberSecurity #Endpoint #InfoSec #InfoStealer #Java #JavaScript #Mac #MacOS #OTX #OpenThreatExchange #RAT #RPC #Rust #SQL #bot #AlienVault

  24. PamStealer: a Rust-based macOS infostealer that validates credentials through PAM

    PamStealer is a two-stage macOS infostealer distributed as a compiled AppleScript impersonating Maccy, a legitimate clipboard manager, hosted on a fake domain. The first stage uses JavaScript for Automation with Objective-C APIs to download payloads while avoiding shell commands. The second stage is a Rust-based Mach-O binary that validates stolen credentials through PAM before harvesting, reads browser databases directly using bundled SQLite, captures clipboard contents repeatedly via pbpaste, and exfiltrates encrypted data using ChaCha20-Poly1305. It establishes persistence through both modern and legacy login item APIs, masquerades as Finder or System Settings, and tricks victims into granting Full Disk Access through counterfeit alerts. The stealer contacts Ethereum RPC endpoints and employs region-based exclusions targeting Apple silicon systems while avoiding Commonwealth of Independent States countries.

    Pulse ID: 6a471de6cf9848f2ef9503c0
    Pulse Link: otx.alienvault.com/pulse/6a471
    Pulse Author: AlienVault
    Created: 2026-07-03 02:26:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #ChaCha20 #Clipboard #CyberSecurity #Endpoint #InfoSec #InfoStealer #Java #JavaScript #Mac #MacOS #OTX #OpenThreatExchange #RAT #RPC #Rust #SQL #bot #AlienVault

  25. PamStealer: a Rust-based macOS infostealer that validates credentials through PAM

    PamStealer is a two-stage macOS infostealer distributed as a compiled AppleScript impersonating Maccy, a legitimate clipboard manager, hosted on a fake domain. The first stage uses JavaScript for Automation with Objective-C APIs to download payloads while avoiding shell commands. The second stage is a Rust-based Mach-O binary that validates stolen credentials through PAM before harvesting, reads browser databases directly using bundled SQLite, captures clipboard contents repeatedly via pbpaste, and exfiltrates encrypted data using ChaCha20-Poly1305. It establishes persistence through both modern and legacy login item APIs, masquerades as Finder or System Settings, and tricks victims into granting Full Disk Access through counterfeit alerts. The stealer contacts Ethereum RPC endpoints and employs region-based exclusions targeting Apple silicon systems while avoiding Commonwealth of Independent States countries.

    Pulse ID: 6a471de6cf9848f2ef9503c0
    Pulse Link: otx.alienvault.com/pulse/6a471
    Pulse Author: AlienVault
    Created: 2026-07-03 02:26:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #ChaCha20 #Clipboard #CyberSecurity #Endpoint #InfoSec #InfoStealer #Java #JavaScript #Mac #MacOS #OTX #OpenThreatExchange #RAT #RPC #Rust #SQL #bot #AlienVault

  26. PamStealer: a Rust-based macOS infostealer that validates credentials through PAM

    PamStealer is a two-stage macOS infostealer distributed as a compiled AppleScript impersonating Maccy, a legitimate clipboard manager, hosted on a fake domain. The first stage uses JavaScript for Automation with Objective-C APIs to download payloads while avoiding shell commands. The second stage is a Rust-based Mach-O binary that validates stolen credentials through PAM before harvesting, reads browser databases directly using bundled SQLite, captures clipboard contents repeatedly via pbpaste, and exfiltrates encrypted data using ChaCha20-Poly1305. It establishes persistence through both modern and legacy login item APIs, masquerades as Finder or System Settings, and tricks victims into granting Full Disk Access through counterfeit alerts. The stealer contacts Ethereum RPC endpoints and employs region-based exclusions targeting Apple silicon systems while avoiding Commonwealth of Independent States countries.

    Pulse ID: 6a471de6cf9848f2ef9503c0
    Pulse Link: otx.alienvault.com/pulse/6a471
    Pulse Author: AlienVault
    Created: 2026-07-03 02:26:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #ChaCha20 #Clipboard #CyberSecurity #Endpoint #InfoSec #InfoStealer #Java #JavaScript #Mac #MacOS #OTX #OpenThreatExchange #RAT #RPC #Rust #SQL #bot #AlienVault

  27. Opera rilascia oggi Paste Protect, una nuova funzione per bloccare i comandi sospetti copiati dai siti web. Questo strumento migliora la sicurezza della #clipboard prevenendo l'esecuzione di script malevoli. #opera #cybersecurity kiro.it/Uod25

  28. Opera rilascia oggi Paste Protect, una nuova funzione per bloccare i comandi sospetti copiati dai siti web. Questo strumento migliora la sicurezza della #clipboard prevenendo l'esecuzione di script malevoli. #opera #cybersecurity kiro.it/Uod25

  29. Opera rilascia oggi Paste Protect, una nuova funzione per bloccare i comandi sospetti copiati dai siti web. Questo strumento migliora la sicurezza della #clipboard prevenendo l'esecuzione di script malevoli. #opera #cybersecurity kiro.it/Uod25

  30. Opera rilascia oggi Paste Protect, una nuova funzione per bloccare i comandi sospetti copiati dai siti web. Questo strumento migliora la sicurezza della #clipboard prevenendo l'esecuzione di script malevoli. #opera #cybersecurity kiro.it/Uod25

  31. Opera rilascia oggi Paste Protect, una nuova funzione per bloccare i comandi sospetti copiati dai siti web. Questo strumento migliora la sicurezza della #clipboard prevenendo l'esecuzione di script malevoli. #opera #cybersecurity kiro.it/Uod25

  32. Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

    In May 2026, an attack campaign targeting banking users in Spain and Portugal was identified involving the Ousaban banking Trojan. The malware, previously active in Brazil, spreads through phishing PDFs that redirect victims to malicious webpages performing environment checks to ensure targets are located in Spain or Portugal. The attack chain involves VBS scripts downloading steganographic images containing the payload, which is then dropped and executed on victims' systems. Ousaban establishes persistence, monitors banking activity across multiple financial institutions, and uses daily-changing DDNS domains to resolve C2 server addresses. The malware employs screenshot capture, keylogging, clipboard injection, and remote control capabilities to steal banking credentials. It utilizes custom encryption algorithms and geofencing techniques to evade detection and limit exposure to intended targets.

    Pulse ID: 6a45880f3df872860c77a553
    Pulse Link: otx.alienvault.com/pulse/6a458
    Pulse Author: AlienVault
    Created: 2026-07-01 21:35:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #Clipboard #CyberSecurity #DNS #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #PDF #Phishing #Portugal #Spain #Trojan #VBS #bot #AlienVault

  33. Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

    In May 2026, an attack campaign targeting banking users in Spain and Portugal was identified involving the Ousaban banking Trojan. The malware, previously active in Brazil, spreads through phishing PDFs that redirect victims to malicious webpages performing environment checks to ensure targets are located in Spain or Portugal. The attack chain involves VBS scripts downloading steganographic images containing the payload, which is then dropped and executed on victims' systems. Ousaban establishes persistence, monitors banking activity across multiple financial institutions, and uses daily-changing DDNS domains to resolve C2 server addresses. The malware employs screenshot capture, keylogging, clipboard injection, and remote control capabilities to steal banking credentials. It utilizes custom encryption algorithms and geofencing techniques to evade detection and limit exposure to intended targets.

    Pulse ID: 6a45880f3df872860c77a553
    Pulse Link: otx.alienvault.com/pulse/6a458
    Pulse Author: AlienVault
    Created: 2026-07-01 21:35:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #Clipboard #CyberSecurity #DNS #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #PDF #Phishing #Portugal #Spain #Trojan #VBS #bot #AlienVault

  34. Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

    In May 2026, an attack campaign targeting banking users in Spain and Portugal was identified involving the Ousaban banking Trojan. The malware, previously active in Brazil, spreads through phishing PDFs that redirect victims to malicious webpages performing environment checks to ensure targets are located in Spain or Portugal. The attack chain involves VBS scripts downloading steganographic images containing the payload, which is then dropped and executed on victims' systems. Ousaban establishes persistence, monitors banking activity across multiple financial institutions, and uses daily-changing DDNS domains to resolve C2 server addresses. The malware employs screenshot capture, keylogging, clipboard injection, and remote control capabilities to steal banking credentials. It utilizes custom encryption algorithms and geofencing techniques to evade detection and limit exposure to intended targets.

    Pulse ID: 6a45880f3df872860c77a553
    Pulse Link: otx.alienvault.com/pulse/6a458
    Pulse Author: AlienVault
    Created: 2026-07-01 21:35:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #Clipboard #CyberSecurity #DNS #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #PDF #Phishing #Portugal #Spain #Trojan #VBS #bot #AlienVault

  35. Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

    In May 2026, an attack campaign targeting banking users in Spain and Portugal was identified involving the Ousaban banking Trojan. The malware, previously active in Brazil, spreads through phishing PDFs that redirect victims to malicious webpages performing environment checks to ensure targets are located in Spain or Portugal. The attack chain involves VBS scripts downloading steganographic images containing the payload, which is then dropped and executed on victims' systems. Ousaban establishes persistence, monitors banking activity across multiple financial institutions, and uses daily-changing DDNS domains to resolve C2 server addresses. The malware employs screenshot capture, keylogging, clipboard injection, and remote control capabilities to steal banking credentials. It utilizes custom encryption algorithms and geofencing techniques to evade detection and limit exposure to intended targets.

    Pulse ID: 6a45880f3df872860c77a553
    Pulse Link: otx.alienvault.com/pulse/6a458
    Pulse Author: AlienVault
    Created: 2026-07-01 21:35:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #Clipboard #CyberSecurity #DNS #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #PDF #Phishing #Portugal #Spain #Trojan #VBS #bot #AlienVault

  36. Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

    In May 2026, an attack campaign targeting banking users in Spain and Portugal was identified involving the Ousaban banking Trojan. The malware, previously active in Brazil, spreads through phishing PDFs that redirect victims to malicious webpages performing environment checks to ensure targets are located in Spain or Portugal. The attack chain involves VBS scripts downloading steganographic images containing the payload, which is then dropped and executed on victims' systems. Ousaban establishes persistence, monitors banking activity across multiple financial institutions, and uses daily-changing DDNS domains to resolve C2 server addresses. The malware employs screenshot capture, keylogging, clipboard injection, and remote control capabilities to steal banking credentials. It utilizes custom encryption algorithms and geofencing techniques to evade detection and limit exposure to intended targets.

    Pulse ID: 6a45880f3df872860c77a553
    Pulse Link: otx.alienvault.com/pulse/6a458
    Pulse Author: AlienVault
    Created: 2026-07-01 21:35:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #Clipboard #CyberSecurity #DNS #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #PDF #Phishing #Portugal #Spain #Trojan #VBS #bot #AlienVault

  37. Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates

    Pulse ID: 6a449688c3850bff89921001
    Pulse Link: otx.alienvault.com/pulse/6a449
    Pulse Author: Tr1sa111
    Created: 2026-07-01 04:24:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chrome #Clipboard #CyberSecurity #FireFox #InfoSec #OTX #OpenThreatExchange #VPN #bot #Tr1sa111

  38. Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates

    Pulse ID: 6a449688c3850bff89921001
    Pulse Link: otx.alienvault.com/pulse/6a449
    Pulse Author: Tr1sa111
    Created: 2026-07-01 04:24:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chrome #Clipboard #CyberSecurity #FireFox #InfoSec #OTX #OpenThreatExchange #VPN #bot #Tr1sa111

  39. Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates

    Pulse ID: 6a449688c3850bff89921001
    Pulse Link: otx.alienvault.com/pulse/6a449
    Pulse Author: Tr1sa111
    Created: 2026-07-01 04:24:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chrome #Clipboard #CyberSecurity #FireFox #InfoSec #OTX #OpenThreatExchange #VPN #bot #Tr1sa111

  40. Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates

    Pulse ID: 6a449688c3850bff89921001
    Pulse Link: otx.alienvault.com/pulse/6a449
    Pulse Author: Tr1sa111
    Created: 2026-07-01 04:24:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chrome #Clipboard #CyberSecurity #FireFox #InfoSec #OTX #OpenThreatExchange #VPN #bot #Tr1sa111

  41. Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates

    Pulse ID: 6a449688c3850bff89921001
    Pulse Link: otx.alienvault.com/pulse/6a449
    Pulse Author: Tr1sa111
    Created: 2026-07-01 04:24:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chrome #Clipboard #CyberSecurity #FireFox #InfoSec #OTX #OpenThreatExchange #VPN #bot #Tr1sa111

  42. Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates

    Malicious browser extensions distributed through Chrome Web Store and Firefox Add-ons marketplaces posed as free VPN services while secretly stealing clipboard data. The Chrome extension, with 146 users, and Firefox extension, with 3,499 users, initially functioned as proxy tools but later incorporated clipboard theft through staged updates. Chrome versions 1.1 onwards and Firefox version 1.3.3 onwards continuously monitored clipboard contents every 500-1500 milliseconds, capturing passwords, API keys, cryptocurrency addresses, and authentication tokens. Stolen data was chunked, tagged with session identifiers, and exfiltrated via HTTP to attacker-controlled infrastructure at multiple IP addresses. Both extensions shared code patterns, infrastructure, and exfiltration endpoints despite appearing as separate products, indicating coordinated malicious operations behind legitimate-appearing privacy tools.

    Pulse ID: 6a43b188e88186c48de04785
    Pulse Link: otx.alienvault.com/pulse/6a43b
    Pulse Author: AlienVault
    Created: 2026-06-30 12:07:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #ChromeExtension #Clipboard #CyberSecurity #Endpoint #FireFox #HTTP #InfoSec #OTX #OpenThreatExchange #Password #Passwords #Privacy #Proxy #RAT #Troll #VPN #Word #bot #cryptocurrency #AlienVault

  43. Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates

    Malicious browser extensions distributed through Chrome Web Store and Firefox Add-ons marketplaces posed as free VPN services while secretly stealing clipboard data. The Chrome extension, with 146 users, and Firefox extension, with 3,499 users, initially functioned as proxy tools but later incorporated clipboard theft through staged updates. Chrome versions 1.1 onwards and Firefox version 1.3.3 onwards continuously monitored clipboard contents every 500-1500 milliseconds, capturing passwords, API keys, cryptocurrency addresses, and authentication tokens. Stolen data was chunked, tagged with session identifiers, and exfiltrated via HTTP to attacker-controlled infrastructure at multiple IP addresses. Both extensions shared code patterns, infrastructure, and exfiltration endpoints despite appearing as separate products, indicating coordinated malicious operations behind legitimate-appearing privacy tools.

    Pulse ID: 6a43b188e88186c48de04785
    Pulse Link: otx.alienvault.com/pulse/6a43b
    Pulse Author: AlienVault
    Created: 2026-06-30 12:07:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #ChromeExtension #Clipboard #CyberSecurity #Endpoint #FireFox #HTTP #InfoSec #OTX #OpenThreatExchange #Password #Passwords #Privacy #Proxy #RAT #Troll #VPN #Word #bot #cryptocurrency #AlienVault