Researchers studying cybersecurity have revealed a new campaign that has been targeting Brazilian users since the beginning of 2025. The goal of the campaign is to infect users with a malicious extension for web browsers that use Chromium and steal user authentication information.
According to a report by security expert Klimentiy Galkin of Positive Technologies, the likelihood of a successful assault increased because some of the phishing emails were sent from the computers of compromised businesses. The attackers employed Mesh Agent, PDQ Connect Agent, and a malicious extension for the browsers Google Chrome, Microsoft Edge, and Brave.
The malicious extension has been downloaded 722 times from various countries, including Brazil, Colombia, the Czech Republic, Mexico, Russia, and Vietnam, according to the Russian cybersecurity firm that is monitoring the activity under the moniker Operation Phantom Enigma read more about Malicious Browser Extensions Infect Over 700 Users Across Latin America Since Early 2025.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
