Netskope Threat Labs @netskopethreatlabs.com · 02/10/2026Stat of the week: DLP events flagging sensitive data exposed publicly in SaaS apps rose 6% week over week. The exposure spans cloud storage, collaboration, webmail, dev tools, CRM, and GenAI apps, where a single public link makes internal data reachable by anyone. 000
Netskope Threat Labs @netskopethreatlabs.com · 01/10/2026Vini Egerland has been tracking the Underground campaign: A crypto-drain operation drains victims' exchange accounts. An injected Vidar-class stealer drives Chrome/Edge from rotating fronted /api/machine gates. It has already stolen ~$100K on-chain. 110
Netskope Threat Labs @netskopethreatlabs.com · 30/09/2026Unruy click-fraud infrastructure picked up new redirect domains. go-us8.gobridges[.]xyz and go-us8.linkhop[.]click, registered the same day in July at the same registrar, joined established go-us8.* hosts on 74.50.88[.]154. Three Unruy downloader samples communicate with that IP. 110
Netskope Threat Labs @netskopethreatlabs.com · 28/09/2026Stat of the week: 295 distinct domains tied to command and control, and malware distribution, turned up in enterprise traffic Netskope saw this week, down 12% from 335 the week before. Hundreds of live C2 domains a week is the steady state. #C2 #threatintel 120
Netskope Threat Labs @netskopethreatlabs.com · 24/09/2026A fake security locker has been circulating using Google Ads to lure victims into clicking. We have seen clicks across more than 619 organization from 250 campaigns, 284 sites hosting the ads, and 457 domains hosting the content. www.netskope.com/blog/a-fake-... 010
Netskope Threat Labs @netskopethreatlabs.com · 23/09/2026ClearFake payload delivery endpoint in use within a day of its registration. Delivery: rehearsal-b[.]com/4qX0LB/tm/oPpE/. ClearFake reads its loader config from BNB Smart Chain contract storage (EtherHiding) 010
Netskope Threat Labs @netskopethreatlabs.com · 17/09/2026Stat of the week: 85.6% of this week's prompt injection alerts related to Anthropic's Claude, out of 18 other apps. 110
Netskope Threat Labs @netskopethreatlabs.com · 15/09/2026ClickFix lures are running off a .beer TLD cluster. aleverifocation[.]beer went into use a day after registration, taking Win+R paste victim checkins at /api.php?s=<token>&_v=<build>. Its IP 178.16.52[.]101 hosts 10+ fake fingerprint/verification/ID pages. 110
Netskope Threat Labs @netskopethreatlabs.com · 10/09/2026Unruy/Cycler click fraud is running C2 inside AWS: Amazon Registrar, EC2, Route 53, CloudFront fronting the payload host. euob.northwavepoint[.]com (CloudFront, JS payloads) and obseu.northwavepoint[.]com (EC2, /ct click tracker). JS payloads are served only under /sxp/i/<md5>.js. 110
Netskope Threat Labs @netskopethreatlabs.com · 07/09/2026Stat of the week: 85% of malware-flagged package downloads Netskope Threat Labs saw last week came from Chrome extensions (crx). Most package supply chain monitoring stops where most of the volume is. #supplychain 110
Netskope Threat Labs @netskopethreatlabs.com · 03/09/2026John Carlo Marquez's latest blog details a growing trend of more than 5,400 compromised websites leveraging the EtherHiding technique and a new campaign that abuses WebRTC to create a covert C2 channel. #EtherHiding #Malware www.netskope.com/blog/malware...netskope.comMalware on the Blockchain: An Ongoing Campaign's New WebRTC TwistEtherHiding, a technique that uses blockchain smart contracts as takedown-resistant payload storage, has been seen across more than 5,400 compromised 010
Netskope Threat Labs @netskopethreatlabs.com · 02/09/2026Jan Michael Alcantara has been tracking NodeStealer for years. The latest variant he analyzed received an AI-assisted upgrade to include more spyware capabilities #malware www.netskope.com/blog/python-...netskope.comPython NodeStealer: AI-Assisted to Full SpywareSince 2023, Netskope Threat Labs has been tracking the Python-based NodeStealer, an infostealer targeting sensitive browser data and Facebook user, and 010
Netskope Threat Labs @netskopethreatlabs.com · 02/09/2026Domains named after plant and place: tamarisknave[.]co, sycamoreitinerary[.]co, yarrowalcove[.]net. Eight of them sit on one Hetzner VPS, each SOA record pointing at the same Proton Mail address. The late-July .top wave rotated off, .net and .co replaced it. 110
Netskope Threat Labs @netskopethreatlabs.com · 31/08/2026Malware is resolving its C2 through the Polygon blockchain as of 2 days ago. An eth_call to a verified contract named extractor returns the domain vg5sgxv[.]lol from getServerURL(), ABI-encoded. 110
Netskope Threat Labs @netskopethreatlabs.com · 31/08/2026A WordPress mass-compromise campaign runs a malicious Service Worker that strips CSP and resolves its ClickFix payload from a Base smart contract. The 9-step chain decodes to the Amatera stealer. See full blog post: www.netskope.com/blog/etherhi...netskope.comEtherHiding in the Browser: ClickFix Chain Ends in AmateraNetskope Threat Labs has been tracking a WordPress mass-compromise campaign affecting hundreds of sites. On each one, a rogue must-use plugin registers a 110
Netskope Threat Labs @netskopethreatlabs.com · 18/08/2026EVM, Solana, and TON all use the same blockchain approach to dead drop resolvers. Netskope's Vinicius Egerland breaks down how it works and what you can do about it. www.netskope.com/blog/blockch...netskope.comBlockchain Dead Drop Resolvers ExplainedA dead drop resolver (DDR) is any mechanism where malware fetches its command and control (C2) address at runtime from a third-party, 020
Netskope Threat Labs @netskopethreatlabs.com · 18/08/2026Netskope observed outbound traffic consistent with malware resolving C2 via BNB Smart Chain contract storage (EtherHiding). The read goes to a public BSC testnet RPC node, so there is no actor domain to blocklist, and testnet contracts draw less scrutiny than mainnet. 210
Netskope Threat Labs @netskopethreatlabs.com · 14/08/2026Stat of the week: 15 distinct cloud apps carried C2 traffic in Netskope telemetry this week, up from 13 last week. Ten are mainstream collaboration and productivity SaaS: Google Drive, OneDrive, SharePoint, Gmail, JIRA, Salesforce. New to the list this week: ChatGPT. #C2 #SaaS 130
Netskope Threat Labs @netskopethreatlabs.com · 11/08/2026The Chrome extension "AI Sidebar with DeepSeek AI" was removed from the Chrome Web Store in Jan 26 for stealing AI conversation content. In July 26 it resumed delivering updates: it monetizes its install base by affiliate link and suppresses navigation to ChatGPT. www.netskope.com/blog/ai-side...netskope.comAI Sidebar Extension Monetizes Its Own UpdatesThe Chrome extension "AI Sidebar with DeepSeek AI" that Google removed from the Chrome Web Store in January 2026 for stealing AI conversation content 110
Netskope Threat Labs @netskopethreatlabs.com · 07/08/2026Stat of the week: Netskope saw 4,995 distinct SHA-256s for one JS malware family, up 47% WoW from 3,393. JS:Trojan.Cryxos.16527, obfuscated JS with browser redirect lures, is repacked so often that nearly every hit is a new hash. Hash-based blocking decays by the day. #malware #JavaScript 110
Netskope Threat Labs @netskopethreatlabs.com · 04/08/2026Shai Hulud: A poisoned npm package wave hardcodes no C2. The stealer issues an eth_call to an Ethereum smart contract that returns the current exfiltration host at runtime. 210
Netskope Threat Labs @netskopethreatlabs.com · 04/08/2026A PDF factory has parked 12,700+ FakeCaptcha lures on Webflow's CDN, indexed by Google. The blog post provides a deep dive into a long-lived TDS that sells the qualifying clicks to several buyers, including the Legion Loader malware downloader. www.netskope.com/blog/fake-ca...netskope.comFake CAPTCHA, Real Business: Traffic Distribution for HireA single PDF factory has stamped out more than 12,700 structurally similar FakeCaptcha documents and parked them on Webflow's content delivery network, 111
Netskope Threat Labs @netskopethreatlabs.com · 31/07/2026Tycoon2FA puts a Cloudflare Turnstile bot check in front of fake Microsoft OAuth authorize endpoints, so scanners stop at the gate while human targets carry on to credential and session token capture. Netskope detections of the pattern rose 78% week over week. #phishing #AiTM 110
Netskope Threat Labs @netskopethreatlabs.com · 29/07/2026Roughly 140 compromised legitimate websites, mostly Spanish, French and Italian small-business and regional media, were serving an injected fake googletagmanager.js, reportedly presenting a ClickFix lure 110
Netskope Threat Labs @netskopethreatlabs.com · 29/07/2026heatherkiln[.]top registered at ~08:00 UTC was already being requested from hundreds of enterprise endpoints that same day, then went quiet 35 hours later. Netskope observed /router/admin-bundle.js, named to pass as a router admin UI bundle. 110
Netskope Threat Labs @netskopethreatlabs.com · 24/07/2026TroyDen's Lure Factory continues to exploit AI hype. Lures trick engineers through fake "Portable Offline LLM" repo that - this again delivers a Prometheus Lua payload. Actor split the LuaJIT runtime into stub and DLL, evading the PE rule. @joshnck traces C2 to a Polygon dead drop. 110
Netskope Threat Labs @netskopethreatlabs.com · 23/07/2026Active phishing wave impersonating Polish marketplaces Allegro and OLX. The multi-brand kit redirects automated scanners to the real site and serves pixel-perfect login clones to human visitors. ~600 DGA-style .lol domains observed. #phishing 110
Netskope Threat Labs @netskopethreatlabs.com · 22/07/2026Taking a look back at the many malicious World Cup scams, including fake FIFA job posting phishing pages. www.netskope.com/blog/world-c... 010
Netskope Threat Labs @netskopethreatlabs.com · 17/06/2026The latest ClickFix attack targeting macOS users bypasses OS-level controls meant to mitigate such threats and deploys an infostealer. www.netskope.com/blog/macos-c... 010
Netskope Threat Labs @netskopethreatlabs.com · 16/06/2026We have been tracking a steady stream of malicious nvim plugins of the past 90 days, all exhibiting the same behavior: - Hosted on GitHub - Contain a renamed LuaJIT interpreter - Prometheus-obfuscated Lua script High-overlap payloads suggests a commodity threat we will continue to see. 110
Netskope Threat Labs @netskopethreatlabs.com · 11/06/2026AI Agents and the OAuth trust problem: How the authorization model already fails at scale, why AI agents make it exponentially worse, and what enterprises can do about it today. www.netskope.com/blog/ai-agen...netskope.comAI Agents and the OAuth Trust Problem at ScaleAt Infosecurity Europe 2026, Netskope Threat Labs presented research on how OAuth authorization abuse has evolved from third-party supply chain breaches 010
Netskope Threat Labs @netskopethreatlabs.com · 08/06/2026Europe Threat Report 2026 - Regulated data drives risk - 59% of violation involve regulated data - AI adoption is near-universal, but governance lags, with 43% still using personal AI apps - Threats on trusted platforms - GitHub and OneDrive remain popular vectors www.netskope.com/resources/th...netskope.comNetskope Threat Labs Report: Europe 2026Learn how organizations in Europe are tackling the evolving cybersecurity landscape, including malware, AI, and data security. 010
Netskope Threat Labs @netskopethreatlabs.com · 14/05/2026The latest round of Shai-Hulud npm worms hit tanstack/history and more than 50 other packages. www.netskope.com/blog/shai-hu...netskope.comShai-Hulud-Style npm Worm Hits @tanstackThe npm packages @tanstack/history (1.161.9, 1.161.12) and more than 50 other packages across the @tanstack, @mistralai, @uipath, @squawk, and safe-action 000