Threat reportPhishingTL-2026-3041
Malicious Bookmark (Bookmarklet) Phishing Campaign Hijacks Logged-In FOMO Web Platform Accounts
Malicious Bookmark (Bookmarklet) Phishing Campaign Hijacks (TL-2026-3041), also tracked as FOMO bookmark phishing, is a high-severity phishing campaign, first published 2026-10-08. It has no confirmed attribution, affects FOMO FOMO web platform (logged-in web sessions), maps to 5 MITRE ATT&CK techniques (T1059.007, T1185, T1204.001), and is covered by 9 detection rules and 6 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 5MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 6Indicators of compromise
Key facts for TL-2026-3041
- Threat ID
- TL-2026-3041
- Also known as
- FOMO bookmark phishing, Bookmarklet phishing against FOMO
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency, web3, social-trading, finance
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 6
Malware and tooling in Malicious Bookmark (Bookmarklet) Phishing Campaign Hijacks
Malware and tooling: JavaScript bookmarklet
How Malicious Bookmark (Bookmarklet) Phishing Campaign Hijacks works
SlowMist flagged an emerging phishing campaign against users of the FOMO web platform on 2026-10-08. Phishing pages show a fake human-verification (CAPTCHA) step that tricks victims into dragging malicious JavaScript into their browser bookmarks; clicking the bookmark 2-3 times hijacks the already logged-in FOMO account and the crypto assets inside are stolen immediately.
On 2026-10-08 SlowMist (via researcher Cos and the @SlowMist_Team account, with a longer Medium analysis titled 'Threat Intelligence Analysis of a Malicious Bookmark Phishing Attack Targeting FOMO Users') warned of bookmark phishing aimed at the FOMO web platform.
Reported attack chain: (1) the victim lands on an attacker-controlled phishing page; (2) the page presents a fake CAPTCHA / human-verification step; (3) the 'verification' instructs the user to drag a snippet of JavaScript into the browser bookmarks bar and save it as a bookmark (a bookmarklet, i.e. a javascript: URI stored as a bookmark); (4) after the user clicks that bookmark 2-3 times while a FOMO web session is open, the script runs in the context of the logged-in FOMO page and the attacker hijacks the account; (5) the attacker immediately steals the crypto assets held in the account. Because the code runs from the user's own bookmark inside the authenticated page, no exploit, malware download or CVE is required and the victim performs the execution step themselves.
SlowMist stated this is not a new technique but a familiar method presented in a new way. The same primitive was documented by SlowMist earlier: its 2022 annual phishing review listed malicious browser bookmarks (JavaScript inserted via phishing pages, fired only when the victim is logged in, used against Discord accounts and project-owner permissions), and in October 2023 a fake-journalist campaign against friend.tech KOLs used a link whose malicious JavaScript was saved by victims and then targeted the account password/2FA and Privy embedded-wallet tokens.
Evidence limits: the primary SlowMist Medium article returned HTTP 403 to automated retrieval, so its full body was not reviewed. None of the secondary outlets (PANews, Coinfomania, KuCoin, ChainCatcher, TokenPost, Phemex) publish phishing domains, script source, exfiltration endpoints, hashes, victim counts or loss totals. Phemex states researchers preserved attacker wallet addresses but did not publish them. No threat actor is named. This incident is distinct from the earlier FomoPeek iOS malware reporting. Detection should therefore focus on behavior (bookmark creation with a javascript: URL, fake-CAPTCHA drag-to-bookmark lure pages, anomalous FOMO session actions) until SlowMist's IOCs are available.
MITRE ATT&CK techniques used in TL-2026-3041
Execution
T1059.007 JavaScript; T1204.001 Malicious Link
Collection
T1185 Browser Session Hijacking
Initial Access
Impact
Affected products and versions in Malicious Bookmark (Bookmarklet) Phishing Campaign Hijacks
- FOMO — FOMO web platform (logged-in web sessions)
Vulnerable versions: Web version; no platform vulnerability reported - abuse of user-executed bookmarklets
Remediation for Malicious Bookmark (Bookmarklet) Phishing Campaign Hijacks
Immediate actions
- Never drag, paste or save JavaScript into browser bookmarks or the console at the request of a web page, including 'human verification' pages
- If you saved such a bookmark: delete it, log out of FOMO and revoke active sessions, and move remaining funds to a wallet you control
- Change FOMO account credentials and review the account for unauthorized activity
Workarounds
- Use a dedicated browser profile for crypto platforms with no bookmarklets saved
- Enterprise browser policy to block or alert on bookmark additions with javascript: schemes where supported
Longer-term hardening
- Reach FOMO only via typed or official bookmarked URLs and verify the domain before logging in
- Platforms: harden web sessions with step-up authentication/confirmation for withdrawals and transfers, and a strict Content-Security-Policy that blocks javascript: URL execution where feasible
- Security teams: monitor browser bookmark stores for javascript: entries on managed endpoints
Timeline of Malicious Bookmark (Bookmarklet) Phishing Campaign Hijacks
- SlowMist's 2022 phishing review (reported 2023-01-17) lists malicious browser bookmarks as a common technique: JavaScript inserted via phishing pages fires when a logged-in Discord user clicks the bookmark.
- October 2023 (day approximate): SlowMist reports a fake-journalist campaign against friend.tech KOLs in which victims saved malicious JavaScript to target account password/2FA and Privy embedded-wallet tokens.
- SlowMist publishes 'Threat Intelligence Analysis of a Malicious Bookmark Phishing Attack Targeting FOMO Users' on Medium (body not retrievable by this pipeline: HTTP 403).
- PANews, ChainCatcher, Phemex, TokenPost, KuCoin and Coinfomania relay the alert; none publish phishing domains, script code, wallet addresses or loss figures.
- @SlowMist_Team publishes a TI Alert on the campaign, stating it is a familiar technique in a new presentation and that a full analysis will follow.
- SlowMist's Cos posts on X that bookmark phishing against the FOMO web platform is emerging (fake human verification, drag JavaScript into bookmarks, 2-3 clicks hijack logged-in account).
Sources cited for Malicious Bookmark (Bookmarklet) Phishing Campaign Hijacks
- SlowMist: Threat Intelligence Analysis of a Malicious Bookmark Phishing Attack Targeting FOMO Users (primary; not retrievable, HTTP 403)
- SlowMist's Cos: Beware of bookmark phishing attacks targeting the FOMO web platform (PANews)
- Beware of Bookmark-Based Phishing Attacks on FOMO Users (Coinfomania)
- SlowMist TI Alert (SlowMist_Team on X)
- Cos (evilcos) original post on X
- SlowMist Warns of Bookmark Phishing Attacks Targeting the FOMO Web Platform (KuCoin)
- SlowMist TI Alert on FOMO bookmark phishing (KuCoin insight)
- Slow Mist Yuxian: FOMO web version suffered bookmark phishing (ChainCatcher)
- FOMO Web Users Face Bookmark Phishing Attack That Steals Crypto (TokenPost)
- FOMO Bookmark Phishing Attack Drains Crypto via Malicious JavaScript (Phemex)
- SlowMist: Analysis of Web3 Phishing Techniques (malicious bookmark precedent)
- SlowMist: Beware of phishing attacks by fake journalists (friend.tech JavaScript bookmark precedent)
Detection coverage for TL-2026-3041
As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3041 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.