New Malware Hijacks Windows with Remote Commands via Deceptive Browser App

New Malware Hijacks Windows with Remote Commands via Deceptive Browser App

First seen 4 Sep 2026, 14:46 UTC Scworldcyberinsider.com 63.5

Article Content

Browse articles
ThreatCluster

Security researchers at Intezer have identified a malicious browser application that can remotely inject keyboard and mouse commands into Windows systems. This malware, disguised as a 'privacy browser,' was distributed after an employee mistyped a URL, leading to an MSIX installer that evaded antivirus detection. The application, built with NW.js, features a hidden input-injection engine that allows attackers to execute commands remotely, similar to a USB Rubber Ducky. The malware waits for user inactivity and hides browser windows to avoid detection. Systems in the US, Canada, and several European countries are affected, with the operation dating back at least ten years. Registry data inadvertently captured during the MSIX package creation exposed developer artifacts, linking this campaign to earlier NW.js-based attacks. The malware's use of the MSIX format helps it appear legitimate, leveraging Microsoft's App Installer for distribution.

Key Points: • Malware masquerades as a privacy browser, injecting commands remotely. • Exploits user error in URL entry, leading to a deceptive MSIX installer. • Targets systems in multiple countries, including the US and Europe.

Ask AI about this cluster

Timeline

2026-09-04
Malware discovery reported
Intezer researchers uncovered a malicious browser application capable of remote command injection into Windows systems.
Cyber Insider
2026-09-04
Malware distribution method identified
The malware was distributed after an employee mistyped a URL, leading to an MSIX installer that avoided antivirus detection.
Scworld
Recent
Operational history linked
The campaign has been active for at least 10 years, with ties to earlier NW.js-based attacks.
Cyber Insider