New Malware Toolkit Redirects Victims to Malicious Sites Without Changing the URL
## Cybersecurity: New Malware Toolkit Threat
Cybersecurity: New Malware Toolkit Threat
A newly discovered malware toolkit, known as Stanley, has been identified on Russian cybercrime forums. This toolkit enables malicious actors to redirect users to fraudulent websites while displaying the legitimate domain name in the browser's address bar.
Stanley is offered for sale at prices ranging from $2,000 to $6,000. It includes a guarantee of passing Google's Chrome Web Store review process, highlighting a significant vulnerability in browser security. The toolkit presents itself as a Chrome extension named "Notely," a note-taking application, and once installed, it can monitor and control all websites visited by the user.
Stanley functions by overlaying a fake website over a legitimate one using a hidden iframe. This creates a convincing illusion, tricking users into entering sensitive information such as login credentials.
The toolkit features a web-based control panel that allows attackers to view infected users, their IP addresses, and browsing history. Attackers can activate hijacking rules and send deceptive Chrome notifications to enhance the phishing attempt.
Stanley was designed to pass Google's review processes, gaining legitimacy and user trust. It first appeared on Thu, Jan 12, 2026, and was advertised for its ability to pass Google Store moderation. The extension accumulated positive reviews due to its legitimate functionality before activating its malicious components.
A newly discovered malware toolkit, known as Stanley, has been identified on Russian cybercrime forums.
The security community reported the toolkit to Google on Thu, Jan 21, 2026, resulting in the command-and-control server going offline the following day. However, the malicious extension continued to be available on the Chrome Web Store.
The extension communicates with its control server every 10 seconds for hijacking instructions. It employs simple techniques, such as spoofed Chrome notifications, to deceive users. The toolkit uses victims' IP addresses for targeting and includes Russian-language comments for fallback domains.
C2 Domain: api.notely.fun C2 Login Panel: notely.fun/login API Endpoint: http://api.notely.fun/api IP Address: 72.61.83.67
Organizations are advised to implement strict extension allowlisting through Chrome Enterprise or Edge for Business to prevent unauthorized extensions. Individual users should regularly audit their extensions, removing any that are unused or request extensive access permissions.
For additional updates and information, follow us on Google News , LinkedIn , and X .
Based on reporting by GBHackers.
