Security· ★★★· bearish·

SlowMist warns of bookmark-based phishing attack on FOMO web app

  • —Attack targets the FOMO web app via malicious browser bookmarks
  • —Victims are tricked into saving malicious JS as a bookmark under the guise of a CAPTCHA
  • —Two to three clicks on the bookmark let attackers hijack the account and drain funds
Why it matters: The scheme needs no software install and bypasses standard checks, so FOMO users should audit their bookmarks and log out.
Source: PANews