
@hunters_ai References:
- The initial publication by @jaimeblascob x.com/jaimeblascob/s…
- great publication including campaign details by @tuckner (Secure Annex) - secureannex.com/blog/cyberhave…
Jaime Blasco@jaimeblascob
Regarding the Cyberhaven chrome extension compromise I have reasons to believe there are other extensions affected. Pivoting by the ip address there are more domains created within the same time range resolving to the same ip address as cyberhavenext[.]pro (cont)
English




