CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (14 April 2026)

Published: Loading…

At a Glance

  • Security researchers identified 108 Chrome extensions using shared cloudapi[.]stream command infrastructure to exfiltrate data from roughly 20,000 installs, forming a globally active campaign.
  • FBI and Indonesian authorities dismantled W3LL phishing infrastructure, a $20 million fraud operation, seizing domains and arresting developer.
  • ShinyHunters claims Rockstar Games breach via Snowflake environment accessed through Anodot tokens, enabling data theft and extortion demands.
  • Booking.com confirmed unauthorised access to reservation systems exposing names, emails, phone numbers and booking details for approximately one million users.
  • Basic-Fit reported system breach exposing banking details, addresses and personal data of one million members across multiple European countries.

Summary

Financial fraud losses reached $16.6 billion in 2024, with MITRE Fight Fraud Framework introduced to unify fraud and cybersecurity incident classification. W3LL phishing infrastructure was dismantled by FBI and Indonesian authorities after operating as a global phishing kit used for credential theft and fraud. Interactive Brokers phishing campaign used IRS-themed emails impersonating W-8BEN renewal requests to capture user credentials through counterfeit login pages targeting non-US account holders globally.

Rockstar Games breach claims involved Snowflake environment access via Anodot tokens, with ShinyHunters alleging data theft and extortion while Rockstar reported limited impact. Booking.com confirmed unauthorised access to reservation systems exposing names, emails, phone numbers and booking details, affecting approximately one million users across Europe. Basic-Fit disclosed a system breach exposing banking details, addresses and personal information of one million members across multiple European countries following investigation.

JanelaRAT banking malware targeted Latin American financial users through MSI droppers, enabling keylogging, overlays and banking data theft across Brazil and Mexico campaigns. APT37 used Facebook-based social engineering to deliver a tampered installer executing shellcode, process injection and AES-encrypted exfiltration via external command infrastructure. 108 Chrome extensions formed a coordinated campaign using cloudapi[.]stream infrastructure to steal Google OAuth tokens, Telegram sessions and browsing data across thousands of installs.

Adobe Acrobat Reader zero-day CVE-2026-34621 was exploited in the wild, enabling arbitrary code execution through malicious PDF documents. CPUID download infrastructure was hijacked to distribute STX RAT malware, replacing legitimate CPU-Z and HWMonitor installers through compromised update channels.

Highlights of the Day

Interactive Brokers phishing campaign uses fake W-8BEN renewal

Cofense Phishing Defence Center identified phishing campaigns impersonating Interactive Brokers, using IRS compliance themed emails requesting W-8BEN renewal from account holders.
Emails contained a 'Renew Certification Now' link leading to a counterfeit Interactive Brokers login page that captured credentials. The messages leveraged W-8BEN tax certification requirements, referencing avoidance of 30% US withholding and tax treaty benefits, sending data to C2 infrastructure.

JanelaRAT malware targets Latin American banking users via MSI dropper

JanelaRAT, a BX RAT variant, targets banking and cryptocurrency users in Latin America, delivered through phishing emails impersonating invoices and redirecting victims to malicious downloads. Campaigns use multi-stage infection chains involving MSI dropper files that deploy obfuscated components, create ActiveX objects, and establish persistence via Startup shortcuts and DLL sideloading. Telemetry records 14,739 attacks in Brazil and 11,695 in Mexico in 2025, with C2-controlled monitoring, overlays, keylogging, and banking process detection features.

APT37 Uses Facebook Pretexting to Deploy Tampered Installer

APT37 used Facebook-based pretexting to target victims, building trust via Messenger before delivering a tampered Wondershare PDFelement installer containing embedded shellcode. The modified installer triggered shellcode execution, created a suspended dism.exe process, injected code via VirtualAllocEx and WriteProcessMemory, and established wininet-based C2 communication. Follow-on activity used a JPG-disguised payload from japanroom[.]com and AES-encrypted exfiltration through Zoho WorkDrive, alongside reconnaissance and data theft across infected systems environments observed.

FBI Dismantles W3LL Phishing Network Behind $20m Fraud

US and Indonesian authorities dismantled the W3LL phishing network responsible for over $20m fraud, with FBI Atlanta seizing the w3ll.store domain. W3LL phishing kit impersonated Microsoft 365 login pages, sold for around $500 on a members-only marketplace operating between 2019 and 2023. After the marketplace shutdown, the operation continued via encrypted messaging apps between 2023 and 2025, targeting over 17,000 victims worldwide.

ShinyHunters Claims Rockstar Breach via Cloud Tokens

ShinyHunters claims breach of Rockstar Games via Snowflake cloud environment accessed through Anodot analytics platform, allegedly using authentication tokens to reach customer accounts. Rockstar Games confirmed limited non-material company information was accessed in connection with a third-party breach and stated there was no impact on operations or players. The group stated stolen data could be leaked under ransom demand, amid reports that similar token-based access affected multiple Snowflake customers via Anodot.

Hackers Access Booking.com User Information in Data Incident

Booking.com notified customers that hackers may have accessed booking information including names, email addresses, phone numbers and reservation details shared with accommodations. The company stated it detected suspicious activity involving unauthorised third parties and said affected reservations were contained with PIN numbers updated and customers informed. Booking.com reported no financial or payment data was accessed while clarifying that the number of affected users and intrusion method remain unclear.

108 Chrome Extensions Exfiltrate Data via Shared Command Infrastructure

Security researchers identified 108 malicious Chrome extensions linked to a coordinated campaign using shared cloudapi[.]stream command-and-control infrastructure across multiple publisher identities. Extensions collectively reached about 20,000 installs and included OAuth-based Google identity theft, Telegram Web session exfiltration, ad injection, and browser backdoor functionality. Persistence and C2 features like loadInfo, user_info, infoURL, and declarativeNetRequest abuse, with data routed to cloudapi stream endpoints controlling sessions and content injection.

Basic-Fit data breach exposes data of one million members

Basic-Fit disclosed that attackers breached its systems and accessed data belonging to around one million members across multiple European countries. Monitoring systems detected the unauthorised access and halted it within minutes, while external investigators confirmed exfiltration of names, addresses, and banking details. Basic-Fit notified data protection authorities and stated no passwords or identity documents were accessed, with no evidence of data publication online yet.

Daily Coverage

Developments
W3Ll TakedownRockstar BreachChrome Extension MalwareBooking.com Access
Vulnerabilities
CVE-2026-32201Microsoft Sharepoint Enterprise Server 2016 16.0.0 (Medium)CVE-2026-21643Forticlientems 7.4.4 (Critical)CVE-2025-0520Showdoc (Critical)CVE-2026-40176CVE-2026-40175Axios < 1.15.0 (Critical)CVE-2026-23666CVE-2026-32157CVE-2026-32190CVE-2026-33114CVE-2026-34621Acrobat Reader (High)
Threat Groups
APT37APT37 is a North Korean statesponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 20162018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean statesponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.