You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Every PhishOps detector maps to a specific threat actor, campaign, or vulnerability disclosure. This document tracks the primary intelligence source for each detection module.
Chrome Extension Detectors
Detector
Threat
Source
Date
Device Code Flow Detection
Storm-2372 OAuth device code phishing
Microsoft Security Blog: "Storm-2372 conducts device code phishing campaign"
March 2026
State Parameter Email Encoding
Storm-2372 state parameter C2 exfiltration
Microsoft MSTIC advisory on OAuth state abuse as data exfiltration channel
March 2, 2026
Blob Credential Page Detection
HTML smuggling terminal page delivery
Mandiant 2025: HTML smuggling by NOBELIUM, TA4557, GhostSpider
2024-2025
Blob Navigation Injection
blob: URL phishing delivery
SquareX YOBB 2025: "Year of Browser Bugs" — blob: URL as phishing mechanism
2025
DNR Header Stripping Audit
QuickLens extension supply chain
Chrome Web Store supply chain attack: declarativeNetRequest used to strip CSP/X-Frame-Options
February 2026
Ownership Drift Detection
Cyberhaven extension compromise
Cyberhaven Chrome extension compromised via developer account takeover
December 2024
C2 Polling Detection
Extension-based C2 infrastructure
Multiple campaigns using Chrome extensions as persistent C2 beacons
2024-2025
GAN-Optimised Page Heuristic
AI-generated phishing pages
Research on adversarial ML-optimised pages with sparse HTML
2025
Credential Focus Monitoring
Agentic guardrail bypass
LLM agents navigating to credential pages and entering sensitive data
2025-2026
ClickFix Clipboard Injection
ClickFix social engineering
Proofpoint: "ClickFix technique tricks users into running malicious commands"
2025
Reverse Proxy Detection
Starkiller PhaaS v6.2.4
Phishing-as-a-Service platform using headless Chrome reverse proxy for AiTM
2025-2026
HTML Smuggling Pattern Detection
ISO/HTML smuggling for RAT delivery
Microsoft MSTIC: ISO and HTML smuggling campaigns for malware delivery
2024-2025
OAuth Scope Analysis
Illicit consent grant attacks
Microsoft: "Detect and remediate illicit consent grants"