ZeroHour

Search: “Malwarebytes Browser Guard”

2 stories

X Money rollout linked to password-reset attacks

X is investigating bulk unsolicited password-reset emails as its X Money payments service expands, with no confirmed breaches or account takeovers yet.

X users began reporting unexpected password-reset emails and codes on September 1, and product engineer Mridul Singhai said attackers appear to believe newly widespread X Money access makes accounts worth targeting. X says it has found no evidence of any breach or successful account takeover, and completing a reset still requires access to the account's email or phone number. X Money offers eligible US users interest-bearing accounts, a Visa debit card, and P2P payments, with Cross River Bank providing banking infrastructure. Malwarebytes warns the reset flood can serve as cover for phishing and urges reset protection, 2FA, and unique passwords.

Malwarebytes Labs · 12d agoPhishing & fraud in the wild

StreamRat Android malware spreads through Meta and TikTok ads

Malwarebytes reports StreamRat Android banking trojan spread via Meta and TikTok ads reaching roughly 570,000 users, mostly in Spain.

Malwarebytes researchers uncovered a malicious advertising campaign on Meta and TikTok promoting a fake free TV-streaming service that delivered the StreamRat Android banking trojan and infostealer. The ads, aimed at Spanish-speaking users with most victims in Spain, reached approximately 570,000 Meta users in a campaign running June 11 through July 3, 2026. The download site detected Android devices and the referral source, then coached users through sideloading steps including enabling installs from unknown sources. StreamRat can monitor the screen, capture typed credentials, display fake login screens, and give attackers remote control, including black-screen and fake Android update overlays.

Malwarebytes Labs · 13d agoMalware in the wild