Cyberattacks targeting browsers have evolved rapidly in recent years, transforming from simple scams to well-organized operations. The emergence of a new threat, known as Stanley, in early 2026 reveals just how serious and complex the digital fraud landscape has become.

Stanley is not a simple piece of malware, but a full-fledged Malware-as-a-Service (MaaS) toolkit, which sells for between $2,000 and $6,000. Most worryingly, it can display fake websites without changing the address bar, creating an extremely convincing illusion of legitimacy.
A scam that fools even experienced users
Unlike classic phishing attacks, where the suspicious URL often betrays the scam, Stanley keeps the legitimate website address visible in the browser bar. The user believes they are on the real site of their bank, email platform or account, while in fact they are interacting with a malicious page designed to steal login credentials and financial information.
See also: New sneaky phishing campaign targets Marriott & Microsoft customers
This technique exploits the trust that users place in the URL bar, which until now was considered one of the key indicators of security.
From Russian-speaking forums in the Chrome Web Store
Stanley first appeared on January 12, 2026, on Russian-language cybercrime forums, with the seller using the alias “Стенли.” However, what’s causing real alarm is the creator’s promise of guaranteed approval in the Chrome Web Store.
This means that the malicious extension can be distributed directly through the official Google store, bypassing users' suspicion and exploiting the platform's reputation for reliability.

Disguise as a useful application
To cover up its activity, Stanley disguises itself as an innocent note-taking and bookmarking app called Notely. This choice is not accidental, as such apps usually request a lot of access permissions, which is not suspicious to most users.
See also: Konni hackers use AI-generated PowerShell backdoor
Varonis researchers were able to identify the toolkit by analyzing both its technical capabilities and its distribution patterns, revealing an extremely well-organized attack infrastructure.
How the violation mechanism works
Stanley is controlled via an online dashboard, where attackers select specific victims and set breach rules. For each target, a legitimate source website and a malicious landing.
When the victim visits the real website, the extension inserts a full-screen iframe that displays the fake page. At the same time, the address bar continues to show the authentic domain, making the scam almost impossible to detect with the naked eye.
Absolute control through extension permissions
The infection mechanism relies on the extensive permissions that a browser extension can request. Upon installation, Stanley gains almost complete control over the user's browsing activity.
The malicious code is executed immediately upon page load, before any legitimate content is displayed. Furthermore, using the IP address as a unique identifier allows attackers to precisely target individuals and correlate their activity across multiple devices and browsers.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Durable infrastructure and thousands of victims
Every ten seconds, the extension communicates with the command and control servers, receiving new instructions. Stanley uses backup domains, automatically switching between them so that it remains active even if authorities take down the main server.
See also: Gmail, Facebook, Instagram, TikTok credentials leaked online
According to the researchers, the tool has already compromised thousands of users, with the dashboard displaying real-time IP addresses, connection status, and activity timestamps.

The structural problem of extension markets
Experts point out that the deeper issue isn't just about Stanley, but the very model of extension marketplaces. Extensions are typically reviewed once upon initial approval, while subsequent updates can pass without significant scrutiny.
For businesses, it is recommended to implement strict policies on allowed extensions. Individual users, on the other hand, are urged to limit the number of extensions installed and carefully consider the permissions they request, as the browser has now become one of the most vulnerable and critical links in digital security.
