PayPal, Netflix, and TikTok users targeted in Matrix Push C2 phishing campaign
The post PayPal, Netflix, and TikTok users targeted in Matrix Push C2 phishing campaign appeared on BitcoinEthereumNews.com.
PayPal, Netflix, and TikTok users have become a new phishing target for hackers using a new tool called Matrix Push C2. According to reports, the tool is accessible as a web-based dashboard. This allows hackers to send notifications, track each victim in real-time, determine which notifications the victims interacted with, and create shortened links using a built-in URL shortening service. Additionally, they track installed browser extensions, including cryptocurrency wallets. In a report, Blackfog researcher Brenda Robb said, “The core of the attack is social engineering, and Matrix Push C2 comes loaded with configurable templates to maximize the credibility of its fake messages […] Attackers can easily theme their phishing notifications and landing pages to impersonate well-known companies and services.” Other well-known brands that support notification verification templates are MetaMask and Cloudflare. The platform also includes an “Analytics & Reports” section that allows its customers to measure the effectiveness of their campaigns and refine them as required. The attack plays out via the web browser as a cross-platform threat When the scammer gets the victim to receive notifications from the site, the attackers take advantage of the web push notification mechanism built into the web browser. They use it to send alerts that appear to have been sent by the operating system or the browser itself. This leverages trusted branding, familiar logos, and convincing language to maintain the ruse. These include alerts about, say, suspicious logins or browser updates, along with a handy “Verify” or “Update” button that, when clicked, takes the victim to a bogus site. With this attack, the entire process takes place through the browser without the need to first infect the victim’s system through another means. In a way, the attack is similar to ClickFix in that users are lured into following specific instructions to compromise their…
Filed under: News - @ November 22, 2025 2:23 pm