Security researchers at Intezer have uncovered a deceptive browser application that can remotely inject keyboard and mouse commands into Windows systems.
The campaign was discovered after an employee mistyped a single character while following setup instructions for a newly purchased mouse. Intezer researchers found that the resulting infection was part of an operation with infrastructure and techniques dating back at least ten years.
Instead of entering the legitimate setup address, the employee typed “.con” rather than “.com”, prompting Google to perform a . A result led through an advertising traffic broker to a page promoting a supposed “privacy browser.” After completing a CAPTCHA, the victim received an MSIX installer.
Intezer says neither the installer nor the installed application attracted meaningful antivirus attention. The MSIX package typically receives between zero and two detections on VirusTotal, while the malicious component remained undetected when the report was published.
The installed application is a functional browser built with NW.js, a framework that combines web technologies with native application capabilities. Researchers found no meaningful privacy-enhancing features.
More concerning is a hidden input-injection engine added to NW.js, which can launch applications and generate synthetic mouse and keyboard activity, effectively giving the operator remote control comparable to a USB Rubber Ducky, but delivered over the internet.
Commands come from the browser's remotely hosted interface rather than files stored locally, allowing operators to change their instructions without updating the installed application. Intezer observed the mechanism modifying default engines and installing browser extensions, but said it is generic enough to control other applications, including launching PowerShell and entering commands.
To avoid attracting attention, the software waits until a computer has been idle for at least seven minutes and moves browser windows off-screen while performing injected actions.
Systems in the United States, Canada, the UK, Germany, France, Italy, Spain, Sweden, the Netherlands, and Australia receive both -engine changes and browser extensions. Some countries are blocked entirely, while users elsewhere receive only the extension.
The malware's use of MSIX also helps it appear trustworthy. Microsoft's App Installer presents packages using a polished Windows interface, and software distributed through the Microsoft Store can inherit Microsoft's signing chain.
However, the attackers made an operational mistake. Registry data accidentally captured while building the MSIX packages exposed details of the developer's everyday computer, including VS Code, Telegram, AdsPower, GeoVPN, WhatsApp, iCloud, and Spotify.
Those artifacts led Intezer to earlier NW.js-based campaigns distributing fake applications associated with WhatsApp, Instagram, Messenger, Tinder, and other services. VirusTotal network records from January 2016 indicate the activity has been running for at least a decade.
Fishbrain data breach exposes user details and password hashes
Brave tests show lower CPU and memory usage than Chrome, Edge, and Firefox
Pegasus zero-click attack infects Serbian activist’s iPhone
WhatsApp rolls out emergency fix for locked Android photo access bug
153 million driver’s licenses exposed in suspected IDScan breach
Lenovo ID flaw let attackers access Dropbox accounts without passwords
Bill specializes in explaining complex technical topics to a non-technical audience. In his 30+ year career, he has covered many of the technological advances that shape our lives. Today, Bill uses those skills to help people protect their privacy and security against the ever-growing assaults on both.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
