This Google phishing page is a thin client - your keystrokes drive a real browser on the attacker's server. https://intel.threadlinqs.com/threat/TL-2026-3036 #ThreatIntel #Google #SocketIO #diffDOM
Explore
DragonDoll hides behind a Chrome update, using AES-256-CBC and RSA-OAEP to protect C2 traffic. It registers devices, gets a client UUID, and can support overlay file retrieval and Socket.IO-based persistence. #DragonDoll #SocketIO #ChromeUpdate
