#clipboard — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #clipboard, aggregated by home.social.
-
https://www.europesays.com/ie/603245/ iOS 27’s new paste shortcut kills the copy-and-paste menu #Apple #clipboard #Éire #IE #Ios27 #Ireland #Mobile #Technology
-
just did Ruby on a clipboard. #oc #pony #mlp #unicorn #comfortcoc #art #headbust #clipboard #traditional #colorpencils
-
just did Ruby on a clipboard. #oc #pony #mlp #unicorn #comfortcoc #art #headbust #clipboard #traditional #colorpencils
-
iOS 27’s new paste shortcut kills the copy-and-paste menu
Copy something, and the iOS 27 paste shortcut now pops up right above your keyboard, ready in a…
#NewsBeep #News #Mobile #Apple #clipboard #iOS27 #Technology #UK #UnitedKingdom
https://www.newsbeep.com/uk/708613/ -
iOS 27’s new paste shortcut kills the copy-and-paste menu
Copy something, and the iOS 27 paste shortcut now pops up right above your keyboard, ready in a…
#NewsBeep #News #Mobile #Apple #AU #Australia #clipboard #iOS27 #Technology
https://www.newsbeep.com/au/820601/ -
iOS 27’s new paste shortcut kills the copy-and-paste menu
Copy something, and the iOS 27 paste shortcut now pops up right above your keyboard, ready in a…
#NewsBeep #News #Mobile #Apple #AU #Australia #clipboard #iOS27 #Technology
https://www.newsbeep.com/au/820601/ -
Need to copy an existing HTML table as text, markdown, and/or comma-separated values to the clipboard? Using just HTML and JavaScript?
Developer advocate, and seasoned tech writer Raymond Camden (Code and Cats) has your back. The post is styled as a tutorial, with ample code samples.
"Copying HTML Tables as Text, Markdown, and CSV"
https://www.raymondcamden.com/2026/07/20/copying-html-tables-as-text-markdown-and-csv
#programming #html #javascript #markdown #csv #text #clipboard
-
Need to copy an existing HTML table as text, markdown, and/or comma-separated values to the clipboard? Using just HTML and JavaScript?
Developer advocate, and seasoned tech writer Raymond Camden (Code and Cats) has your back. The post is styled as a tutorial, with ample code samples.
"Copying HTML Tables as Text, Markdown, and CSV"
https://www.raymondcamden.com/2026/07/20/copying-html-tables-as-text-markdown-and-csv
#programming #html #javascript #markdown #csv #text #clipboard
-
Need to copy an existing HTML table as text, markdown, and/or comma-separated values to the clipboard? Using just HTML and JavaScript?
Developer advocate, and seasoned tech writer Raymond Camden (Code and Cats) has your back. The post is styled as a tutorial, with ample code samples.
"Copying HTML Tables as Text, Markdown, and CSV"
https://www.raymondcamden.com/2026/07/20/copying-html-tables-as-text-markdown-and-csv
#programming #html #javascript #markdown #csv #text #clipboard
-
Need to copy an existing HTML table as text, markdown, and/or comma-separated values to the clipboard? Using just HTML and JavaScript?
Developer advocate, and seasoned tech writer Raymond Camden (Code and Cats) has your back. The post is styled as a tutorial, with ample code samples.
"Copying HTML Tables as Text, Markdown, and CSV"
https://www.raymondcamden.com/2026/07/20/copying-html-tables-as-text-markdown-and-csv
#programming #html #javascript #markdown #csv #text #clipboard
-
Need to copy an existing HTML table as text, markdown, and/or comma-separated values to the clipboard? Using just HTML and JavaScript?
Developer advocate, and seasoned tech writer Raymond Camden (Code and Cats) has your back. The post is styled as a tutorial, with ample code samples.
"Copying HTML Tables as Text, Markdown, and CSV"
https://www.raymondcamden.com/2026/07/20/copying-html-tables-as-text-markdown-and-csv
#programming #html #javascript #markdown #csv #text #clipboard
-
UniClipboard is an open-source clipboard sync tool for securely sharing text, images, and files across your devices.
It uses end-to-end encryption, works on Windows, macOS, Linux, Android, and iOS, and doesn't require a cloud account.
More details: https://digitalescapetools.com/tools/tool.html?id=uniclipboard
#OpenSource #Privacy #Productivity #Clipboard #Windows #Linux #macOS #Android #iOS
-
UniClipboard is an open-source clipboard sync tool for securely sharing text, images, and files across your devices.
It uses end-to-end encryption, works on Windows, macOS, Linux, Android, and iOS, and doesn't require a cloud account.
More details: https://digitalescapetools.com/tools/tool.html?id=uniclipboard
#OpenSource #Privacy #Productivity #Clipboard #Windows #Linux #macOS #Android #iOS
-
UniClipboard is an open-source clipboard sync tool for securely sharing text, images, and files across your devices.
It uses end-to-end encryption, works on Windows, macOS, Linux, Android, and iOS, and doesn't require a cloud account.
More details: https://digitalescapetools.com/tools/tool.html?id=uniclipboard
#OpenSource #Privacy #Productivity #Clipboard #Windows #Linux #macOS #Android #iOS
-
UniClipboard is an open-source clipboard sync tool for securely sharing text, images, and files across your devices.
It uses end-to-end encryption, works on Windows, macOS, Linux, Android, and iOS, and doesn't require a cloud account.
More details: https://digitalescapetools.com/tools/tool.html?id=uniclipboard
#OpenSource #Privacy #Productivity #Clipboard #Windows #Linux #macOS #Android #iOS
-
UniClipboard is an open-source clipboard sync tool for securely sharing text, images, and files across your devices.
It uses end-to-end encryption, works on Windows, macOS, Linux, Android, and iOS, and doesn't require a cloud account.
More details: https://digitalescapetools.com/tools/tool.html?id=uniclipboard
#OpenSource #Privacy #Productivity #Clipboard #Windows #Linux #macOS #Android #iOS
-
CopyQ: il superpotere #OpenSource che manca alla tua #Clipboard
#software #windows #linux #macos @opensourcehttps://webappsmagazine.blogspot.com/2026/07/copyq-il-superpotere-open-source-che.html
-
CopyQ: il superpotere #OpenSource che manca alla tua #Clipboard
#software #windows #linux #macos @opensourcehttps://webappsmagazine.blogspot.com/2026/07/copyq-il-superpotere-open-source-che.html
-
CopyQ: il superpotere #OpenSource che manca alla tua #Clipboard
#software #windows #linux #macos @opensourcehttps://webappsmagazine.blogspot.com/2026/07/copyq-il-superpotere-open-source-che.html
-
CopyQ: il superpotere #OpenSource che manca alla tua #Clipboard
#software #windows #linux #macos @opensourcehttps://webappsmagazine.blogspot.com/2026/07/copyq-il-superpotere-open-source-che.html
-
Contagious Interview malware in SVG images: DPRK campaign
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.
Pulse ID: 6a5a8ba0229db5a5b2686baa
Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa
Pulse Author: AlienVault
Created: 2026-07-17 20:08:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
-
Contagious Interview malware in SVG images: DPRK campaign
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.
Pulse ID: 6a5a8ba0229db5a5b2686baa
Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa
Pulse Author: AlienVault
Created: 2026-07-17 20:08:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
-
Contagious Interview malware in SVG images: DPRK campaign
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.
Pulse ID: 6a5a8ba0229db5a5b2686baa
Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa
Pulse Author: AlienVault
Created: 2026-07-17 20:08:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
-
Contagious Interview malware in SVG images: DPRK campaign
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.
Pulse ID: 6a5a8ba0229db5a5b2686baa
Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa
Pulse Author: AlienVault
Created: 2026-07-17 20:08:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
-
Contagious Interview malware in SVG images: DPRK campaign
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.
Pulse ID: 6a5a8ba0229db5a5b2686baa
Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa
Pulse Author: AlienVault
Created: 2026-07-17 20:08:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
-
Link to Pane: буфер обмена Mac Android через протокол Microsoft (потому что иначе — pain (икра слов)
Привет, Хабр! Пришло время реверсить протоколы снова. Apple я делал. Google тоже. Угадайте какая компания следующая?
https://habr.com/ru/articles/1060248/
#phone_link #link_to_windows #clipboard #macos #reverse_engineering #microsoft #shareware
-
Link to Pane: буфер обмена Mac Android через протокол Microsoft (потому что иначе — pain (икра слов)
Привет, Хабр! Пришло время реверсить протоколы снова. Apple я делал. Google тоже. Угадайте какая компания следующая?
https://habr.com/ru/articles/1060248/
#phone_link #link_to_windows #clipboard #macos #reverse_engineering #microsoft #shareware
-
Link to Pane: буфер обмена Mac Android через протокол Microsoft (потому что иначе — pain (икра слов)
Привет, Хабр! Пришло время реверсить протоколы снова. Apple я делал. Google тоже. Угадайте какая компания следующая?
https://habr.com/ru/articles/1060248/
#phone_link #link_to_windows #clipboard #macos #reverse_engineering #microsoft #shareware
-
PamStealer: a Rust-based macOS infostealer that validates credentials through PAM
PamStealer is a two-stage macOS infostealer distributed as a compiled AppleScript impersonating Maccy, a legitimate clipboard manager, hosted on a fake domain. The first stage uses JavaScript for Automation with Objective-C APIs to download payloads while avoiding shell commands. The second stage is a Rust-based Mach-O binary that validates stolen credentials through PAM before harvesting, reads browser databases directly using bundled SQLite, captures clipboard contents repeatedly via pbpaste, and exfiltrates encrypted data using ChaCha20-Poly1305. It establishes persistence through both modern and legacy login item APIs, masquerades as Finder or System Settings, and tricks victims into granting Full Disk Access through counterfeit alerts. The stealer contacts Ethereum RPC endpoints and employs region-based exclusions targeting Apple silicon systems while avoiding Commonwealth of Independent States countries.
Pulse ID: 6a471de6cf9848f2ef9503c0
Pulse Link: https://otx.alienvault.com/pulse/6a471de6cf9848f2ef9503c0
Pulse Author: AlienVault
Created: 2026-07-03 02:26:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #ChaCha20 #Clipboard #CyberSecurity #Endpoint #InfoSec #InfoStealer #Java #JavaScript #Mac #MacOS #OTX #OpenThreatExchange #RAT #RPC #Rust #SQL #bot #AlienVault
-
PamStealer: a Rust-based macOS infostealer that validates credentials through PAM
PamStealer is a two-stage macOS infostealer distributed as a compiled AppleScript impersonating Maccy, a legitimate clipboard manager, hosted on a fake domain. The first stage uses JavaScript for Automation with Objective-C APIs to download payloads while avoiding shell commands. The second stage is a Rust-based Mach-O binary that validates stolen credentials through PAM before harvesting, reads browser databases directly using bundled SQLite, captures clipboard contents repeatedly via pbpaste, and exfiltrates encrypted data using ChaCha20-Poly1305. It establishes persistence through both modern and legacy login item APIs, masquerades as Finder or System Settings, and tricks victims into granting Full Disk Access through counterfeit alerts. The stealer contacts Ethereum RPC endpoints and employs region-based exclusions targeting Apple silicon systems while avoiding Commonwealth of Independent States countries.
Pulse ID: 6a471de6cf9848f2ef9503c0
Pulse Link: https://otx.alienvault.com/pulse/6a471de6cf9848f2ef9503c0
Pulse Author: AlienVault
Created: 2026-07-03 02:26:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #ChaCha20 #Clipboard #CyberSecurity #Endpoint #InfoSec #InfoStealer #Java #JavaScript #Mac #MacOS #OTX #OpenThreatExchange #RAT #RPC #Rust #SQL #bot #AlienVault
-
PamStealer: a Rust-based macOS infostealer that validates credentials through PAM
PamStealer is a two-stage macOS infostealer distributed as a compiled AppleScript impersonating Maccy, a legitimate clipboard manager, hosted on a fake domain. The first stage uses JavaScript for Automation with Objective-C APIs to download payloads while avoiding shell commands. The second stage is a Rust-based Mach-O binary that validates stolen credentials through PAM before harvesting, reads browser databases directly using bundled SQLite, captures clipboard contents repeatedly via pbpaste, and exfiltrates encrypted data using ChaCha20-Poly1305. It establishes persistence through both modern and legacy login item APIs, masquerades as Finder or System Settings, and tricks victims into granting Full Disk Access through counterfeit alerts. The stealer contacts Ethereum RPC endpoints and employs region-based exclusions targeting Apple silicon systems while avoiding Commonwealth of Independent States countries.
Pulse ID: 6a471de6cf9848f2ef9503c0
Pulse Link: https://otx.alienvault.com/pulse/6a471de6cf9848f2ef9503c0
Pulse Author: AlienVault
Created: 2026-07-03 02:26:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #ChaCha20 #Clipboard #CyberSecurity #Endpoint #InfoSec #InfoStealer #Java #JavaScript #Mac #MacOS #OTX #OpenThreatExchange #RAT #RPC #Rust #SQL #bot #AlienVault
-
PamStealer: a Rust-based macOS infostealer that validates credentials through PAM
PamStealer is a two-stage macOS infostealer distributed as a compiled AppleScript impersonating Maccy, a legitimate clipboard manager, hosted on a fake domain. The first stage uses JavaScript for Automation with Objective-C APIs to download payloads while avoiding shell commands. The second stage is a Rust-based Mach-O binary that validates stolen credentials through PAM before harvesting, reads browser databases directly using bundled SQLite, captures clipboard contents repeatedly via pbpaste, and exfiltrates encrypted data using ChaCha20-Poly1305. It establishes persistence through both modern and legacy login item APIs, masquerades as Finder or System Settings, and tricks victims into granting Full Disk Access through counterfeit alerts. The stealer contacts Ethereum RPC endpoints and employs region-based exclusions targeting Apple silicon systems while avoiding Commonwealth of Independent States countries.
Pulse ID: 6a471de6cf9848f2ef9503c0
Pulse Link: https://otx.alienvault.com/pulse/6a471de6cf9848f2ef9503c0
Pulse Author: AlienVault
Created: 2026-07-03 02:26:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #ChaCha20 #Clipboard #CyberSecurity #Endpoint #InfoSec #InfoStealer #Java #JavaScript #Mac #MacOS #OTX #OpenThreatExchange #RAT #RPC #Rust #SQL #bot #AlienVault
-
PamStealer: a Rust-based macOS infostealer that validates credentials through PAM
PamStealer is a two-stage macOS infostealer distributed as a compiled AppleScript impersonating Maccy, a legitimate clipboard manager, hosted on a fake domain. The first stage uses JavaScript for Automation with Objective-C APIs to download payloads while avoiding shell commands. The second stage is a Rust-based Mach-O binary that validates stolen credentials through PAM before harvesting, reads browser databases directly using bundled SQLite, captures clipboard contents repeatedly via pbpaste, and exfiltrates encrypted data using ChaCha20-Poly1305. It establishes persistence through both modern and legacy login item APIs, masquerades as Finder or System Settings, and tricks victims into granting Full Disk Access through counterfeit alerts. The stealer contacts Ethereum RPC endpoints and employs region-based exclusions targeting Apple silicon systems while avoiding Commonwealth of Independent States countries.
Pulse ID: 6a471de6cf9848f2ef9503c0
Pulse Link: https://otx.alienvault.com/pulse/6a471de6cf9848f2ef9503c0
Pulse Author: AlienVault
Created: 2026-07-03 02:26:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #ChaCha20 #Clipboard #CyberSecurity #Endpoint #InfoSec #InfoStealer #Java #JavaScript #Mac #MacOS #OTX #OpenThreatExchange #RAT #RPC #Rust #SQL #bot #AlienVault
-
Opera rilascia oggi Paste Protect, una nuova funzione per bloccare i comandi sospetti copiati dai siti web. Questo strumento migliora la sicurezza della #clipboard prevenendo l'esecuzione di script malevoli. #opera #cybersecurity https://kiro.it/Uod25
-
Opera rilascia oggi Paste Protect, una nuova funzione per bloccare i comandi sospetti copiati dai siti web. Questo strumento migliora la sicurezza della #clipboard prevenendo l'esecuzione di script malevoli. #opera #cybersecurity https://kiro.it/Uod25
-
Opera rilascia oggi Paste Protect, una nuova funzione per bloccare i comandi sospetti copiati dai siti web. Questo strumento migliora la sicurezza della #clipboard prevenendo l'esecuzione di script malevoli. #opera #cybersecurity https://kiro.it/Uod25
-
Opera rilascia oggi Paste Protect, una nuova funzione per bloccare i comandi sospetti copiati dai siti web. Questo strumento migliora la sicurezza della #clipboard prevenendo l'esecuzione di script malevoli. #opera #cybersecurity https://kiro.it/Uod25
-
Opera rilascia oggi Paste Protect, una nuova funzione per bloccare i comandi sospetti copiati dai siti web. Questo strumento migliora la sicurezza della #clipboard prevenendo l'esecuzione di script malevoli. #opera #cybersecurity https://kiro.it/Uod25
-
Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula
In May 2026, an attack campaign targeting banking users in Spain and Portugal was identified involving the Ousaban banking Trojan. The malware, previously active in Brazil, spreads through phishing PDFs that redirect victims to malicious webpages performing environment checks to ensure targets are located in Spain or Portugal. The attack chain involves VBS scripts downloading steganographic images containing the payload, which is then dropped and executed on victims' systems. Ousaban establishes persistence, monitors banking activity across multiple financial institutions, and uses daily-changing DDNS domains to resolve C2 server addresses. The malware employs screenshot capture, keylogging, clipboard injection, and remote control capabilities to steal banking credentials. It utilizes custom encryption algorithms and geofencing techniques to evade detection and limit exposure to intended targets.
Pulse ID: 6a45880f3df872860c77a553
Pulse Link: https://otx.alienvault.com/pulse/6a45880f3df872860c77a553
Pulse Author: AlienVault
Created: 2026-07-01 21:35:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #BankingTrojan #Brazil #Clipboard #CyberSecurity #DNS #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #PDF #Phishing #Portugal #Spain #Trojan #VBS #bot #AlienVault
-
Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula
In May 2026, an attack campaign targeting banking users in Spain and Portugal was identified involving the Ousaban banking Trojan. The malware, previously active in Brazil, spreads through phishing PDFs that redirect victims to malicious webpages performing environment checks to ensure targets are located in Spain or Portugal. The attack chain involves VBS scripts downloading steganographic images containing the payload, which is then dropped and executed on victims' systems. Ousaban establishes persistence, monitors banking activity across multiple financial institutions, and uses daily-changing DDNS domains to resolve C2 server addresses. The malware employs screenshot capture, keylogging, clipboard injection, and remote control capabilities to steal banking credentials. It utilizes custom encryption algorithms and geofencing techniques to evade detection and limit exposure to intended targets.
Pulse ID: 6a45880f3df872860c77a553
Pulse Link: https://otx.alienvault.com/pulse/6a45880f3df872860c77a553
Pulse Author: AlienVault
Created: 2026-07-01 21:35:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #BankingTrojan #Brazil #Clipboard #CyberSecurity #DNS #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #PDF #Phishing #Portugal #Spain #Trojan #VBS #bot #AlienVault
-
Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula
In May 2026, an attack campaign targeting banking users in Spain and Portugal was identified involving the Ousaban banking Trojan. The malware, previously active in Brazil, spreads through phishing PDFs that redirect victims to malicious webpages performing environment checks to ensure targets are located in Spain or Portugal. The attack chain involves VBS scripts downloading steganographic images containing the payload, which is then dropped and executed on victims' systems. Ousaban establishes persistence, monitors banking activity across multiple financial institutions, and uses daily-changing DDNS domains to resolve C2 server addresses. The malware employs screenshot capture, keylogging, clipboard injection, and remote control capabilities to steal banking credentials. It utilizes custom encryption algorithms and geofencing techniques to evade detection and limit exposure to intended targets.
Pulse ID: 6a45880f3df872860c77a553
Pulse Link: https://otx.alienvault.com/pulse/6a45880f3df872860c77a553
Pulse Author: AlienVault
Created: 2026-07-01 21:35:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #BankingTrojan #Brazil #Clipboard #CyberSecurity #DNS #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #PDF #Phishing #Portugal #Spain #Trojan #VBS #bot #AlienVault
-
Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula
In May 2026, an attack campaign targeting banking users in Spain and Portugal was identified involving the Ousaban banking Trojan. The malware, previously active in Brazil, spreads through phishing PDFs that redirect victims to malicious webpages performing environment checks to ensure targets are located in Spain or Portugal. The attack chain involves VBS scripts downloading steganographic images containing the payload, which is then dropped and executed on victims' systems. Ousaban establishes persistence, monitors banking activity across multiple financial institutions, and uses daily-changing DDNS domains to resolve C2 server addresses. The malware employs screenshot capture, keylogging, clipboard injection, and remote control capabilities to steal banking credentials. It utilizes custom encryption algorithms and geofencing techniques to evade detection and limit exposure to intended targets.
Pulse ID: 6a45880f3df872860c77a553
Pulse Link: https://otx.alienvault.com/pulse/6a45880f3df872860c77a553
Pulse Author: AlienVault
Created: 2026-07-01 21:35:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #BankingTrojan #Brazil #Clipboard #CyberSecurity #DNS #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #PDF #Phishing #Portugal #Spain #Trojan #VBS #bot #AlienVault
-
Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula
In May 2026, an attack campaign targeting banking users in Spain and Portugal was identified involving the Ousaban banking Trojan. The malware, previously active in Brazil, spreads through phishing PDFs that redirect victims to malicious webpages performing environment checks to ensure targets are located in Spain or Portugal. The attack chain involves VBS scripts downloading steganographic images containing the payload, which is then dropped and executed on victims' systems. Ousaban establishes persistence, monitors banking activity across multiple financial institutions, and uses daily-changing DDNS domains to resolve C2 server addresses. The malware employs screenshot capture, keylogging, clipboard injection, and remote control capabilities to steal banking credentials. It utilizes custom encryption algorithms and geofencing techniques to evade detection and limit exposure to intended targets.
Pulse ID: 6a45880f3df872860c77a553
Pulse Link: https://otx.alienvault.com/pulse/6a45880f3df872860c77a553
Pulse Author: AlienVault
Created: 2026-07-01 21:35:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #BankingTrojan #Brazil #Clipboard #CyberSecurity #DNS #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #PDF #Phishing #Portugal #Spain #Trojan #VBS #bot #AlienVault
-
Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates
Pulse ID: 6a449688c3850bff89921001
Pulse Link: https://otx.alienvault.com/pulse/6a449688c3850bff89921001
Pulse Author: Tr1sa111
Created: 2026-07-01 04:24:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #Clipboard #CyberSecurity #FireFox #InfoSec #OTX #OpenThreatExchange #VPN #bot #Tr1sa111
-
Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates
Pulse ID: 6a449688c3850bff89921001
Pulse Link: https://otx.alienvault.com/pulse/6a449688c3850bff89921001
Pulse Author: Tr1sa111
Created: 2026-07-01 04:24:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #Clipboard #CyberSecurity #FireFox #InfoSec #OTX #OpenThreatExchange #VPN #bot #Tr1sa111
-
Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates
Pulse ID: 6a449688c3850bff89921001
Pulse Link: https://otx.alienvault.com/pulse/6a449688c3850bff89921001
Pulse Author: Tr1sa111
Created: 2026-07-01 04:24:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #Clipboard #CyberSecurity #FireFox #InfoSec #OTX #OpenThreatExchange #VPN #bot #Tr1sa111
-
Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates
Pulse ID: 6a449688c3850bff89921001
Pulse Link: https://otx.alienvault.com/pulse/6a449688c3850bff89921001
Pulse Author: Tr1sa111
Created: 2026-07-01 04:24:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #Clipboard #CyberSecurity #FireFox #InfoSec #OTX #OpenThreatExchange #VPN #bot #Tr1sa111
-
Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates
Pulse ID: 6a449688c3850bff89921001
Pulse Link: https://otx.alienvault.com/pulse/6a449688c3850bff89921001
Pulse Author: Tr1sa111
Created: 2026-07-01 04:24:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #Clipboard #CyberSecurity #FireFox #InfoSec #OTX #OpenThreatExchange #VPN #bot #Tr1sa111
-
Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates
Malicious browser extensions distributed through Chrome Web Store and Firefox Add-ons marketplaces posed as free VPN services while secretly stealing clipboard data. The Chrome extension, with 146 users, and Firefox extension, with 3,499 users, initially functioned as proxy tools but later incorporated clipboard theft through staged updates. Chrome versions 1.1 onwards and Firefox version 1.3.3 onwards continuously monitored clipboard contents every 500-1500 milliseconds, capturing passwords, API keys, cryptocurrency addresses, and authentication tokens. Stolen data was chunked, tagged with session identifiers, and exfiltrated via HTTP to attacker-controlled infrastructure at multiple IP addresses. Both extensions shared code patterns, infrastructure, and exfiltration endpoints despite appearing as separate products, indicating coordinated malicious operations behind legitimate-appearing privacy tools.
Pulse ID: 6a43b188e88186c48de04785
Pulse Link: https://otx.alienvault.com/pulse/6a43b188e88186c48de04785
Pulse Author: AlienVault
Created: 2026-06-30 12:07:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #ChromeExtension #Clipboard #CyberSecurity #Endpoint #FireFox #HTTP #InfoSec #OTX #OpenThreatExchange #Password #Passwords #Privacy #Proxy #RAT #Troll #VPN #Word #bot #cryptocurrency #AlienVault
-
Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates
Malicious browser extensions distributed through Chrome Web Store and Firefox Add-ons marketplaces posed as free VPN services while secretly stealing clipboard data. The Chrome extension, with 146 users, and Firefox extension, with 3,499 users, initially functioned as proxy tools but later incorporated clipboard theft through staged updates. Chrome versions 1.1 onwards and Firefox version 1.3.3 onwards continuously monitored clipboard contents every 500-1500 milliseconds, capturing passwords, API keys, cryptocurrency addresses, and authentication tokens. Stolen data was chunked, tagged with session identifiers, and exfiltrated via HTTP to attacker-controlled infrastructure at multiple IP addresses. Both extensions shared code patterns, infrastructure, and exfiltration endpoints despite appearing as separate products, indicating coordinated malicious operations behind legitimate-appearing privacy tools.
Pulse ID: 6a43b188e88186c48de04785
Pulse Link: https://otx.alienvault.com/pulse/6a43b188e88186c48de04785
Pulse Author: AlienVault
Created: 2026-06-30 12:07:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #ChromeExtension #Clipboard #CyberSecurity #Endpoint #FireFox #HTTP #InfoSec #OTX #OpenThreatExchange #Password #Passwords #Privacy #Proxy #RAT #Troll #VPN #Word #bot #cryptocurrency #AlienVault