Threat reportPhishingTL-2026-3041

Malicious Bookmark (Bookmarklet) Phishing Campaign Hijacks Logged-In FOMO Web Platform Accounts

highACTIVE

Malicious Bookmark (Bookmarklet) Phishing Campaign Hijacks (TL-2026-3041), also tracked as FOMO bookmark phishing, is a high-severity phishing campaign, first published 2026-10-08. It has no confirmed attribution, affects FOMO FOMO web platform (logged-in web sessions), maps to 5 MITRE ATT&CK techniques (T1059.007, T1185, T1204.001), and is covered by 9 detection rules and 6 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
5MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
6Indicators of compromise

Key facts for TL-2026-3041

Threat ID
TL-2026-3041
Also known as
FOMO bookmark phishing, Bookmarklet phishing against FOMO
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
cryptocurrency, web3, social-trading, finance
Target regions
Global
Detection rules
9
Indicators of compromise
6

Malware and tooling in Malicious Bookmark (Bookmarklet) Phishing Campaign Hijacks

Malware and tooling: JavaScript bookmarklet

How Malicious Bookmark (Bookmarklet) Phishing Campaign Hijacks works

SlowMist flagged an emerging phishing campaign against users of the FOMO web platform on 2026-10-08. Phishing pages show a fake human-verification (CAPTCHA) step that tricks victims into dragging malicious JavaScript into their browser bookmarks; clicking the bookmark 2-3 times hijacks the already logged-in FOMO account and the crypto assets inside are stolen immediately.

On 2026-10-08 SlowMist (via researcher Cos and the @SlowMist_Team account, with a longer Medium analysis titled 'Threat Intelligence Analysis of a Malicious Bookmark Phishing Attack Targeting FOMO Users') warned of bookmark phishing aimed at the FOMO web platform.

Reported attack chain: (1) the victim lands on an attacker-controlled phishing page; (2) the page presents a fake CAPTCHA / human-verification step; (3) the 'verification' instructs the user to drag a snippet of JavaScript into the browser bookmarks bar and save it as a bookmark (a bookmarklet, i.e. a javascript: URI stored as a bookmark); (4) after the user clicks that bookmark 2-3 times while a FOMO web session is open, the script runs in the context of the logged-in FOMO page and the attacker hijacks the account; (5) the attacker immediately steals the crypto assets held in the account. Because the code runs from the user's own bookmark inside the authenticated page, no exploit, malware download or CVE is required and the victim performs the execution step themselves.

SlowMist stated this is not a new technique but a familiar method presented in a new way. The same primitive was documented by SlowMist earlier: its 2022 annual phishing review listed malicious browser bookmarks (JavaScript inserted via phishing pages, fired only when the victim is logged in, used against Discord accounts and project-owner permissions), and in October 2023 a fake-journalist campaign against friend.tech KOLs used a link whose malicious JavaScript was saved by victims and then targeted the account password/2FA and Privy embedded-wallet tokens.

Evidence limits: the primary SlowMist Medium article returned HTTP 403 to automated retrieval, so its full body was not reviewed. None of the secondary outlets (PANews, Coinfomania, KuCoin, ChainCatcher, TokenPost, Phemex) publish phishing domains, script source, exfiltration endpoints, hashes, victim counts or loss totals. Phemex states researchers preserved attacker wallet addresses but did not publish them. No threat actor is named. This incident is distinct from the earlier FomoPeek iOS malware reporting. Detection should therefore focus on behavior (bookmark creation with a javascript: URL, fake-CAPTCHA drag-to-bookmark lure pages, anomalous FOMO session actions) until SlowMist's IOCs are available.

MITRE ATT&CK techniques used in TL-2026-3041

Execution

T1059.007 JavaScript; T1204.001 Malicious Link

Collection

T1185 Browser Session Hijacking

Initial Access

T1566 Phishing

Impact

T1657 Financial Theft

Affected products and versions in Malicious Bookmark (Bookmarklet) Phishing Campaign Hijacks

  • FOMO — FOMO web platform (logged-in web sessions)
    Vulnerable versions: Web version; no platform vulnerability reported - abuse of user-executed bookmarklets

Remediation for Malicious Bookmark (Bookmarklet) Phishing Campaign Hijacks

Immediate actions

  • Never drag, paste or save JavaScript into browser bookmarks or the console at the request of a web page, including 'human verification' pages
  • If you saved such a bookmark: delete it, log out of FOMO and revoke active sessions, and move remaining funds to a wallet you control
  • Change FOMO account credentials and review the account for unauthorized activity

Workarounds

  • Use a dedicated browser profile for crypto platforms with no bookmarklets saved
  • Enterprise browser policy to block or alert on bookmark additions with javascript: schemes where supported

Longer-term hardening

  • Reach FOMO only via typed or official bookmarked URLs and verify the domain before logging in
  • Platforms: harden web sessions with step-up authentication/confirmation for withdrawals and transfers, and a strict Content-Security-Policy that blocks javascript: URL execution where feasible
  • Security teams: monitor browser bookmark stores for javascript: entries on managed endpoints

Timeline of Malicious Bookmark (Bookmarklet) Phishing Campaign Hijacks

  • SlowMist's 2022 phishing review (reported 2023-01-17) lists malicious browser bookmarks as a common technique: JavaScript inserted via phishing pages fires when a logged-in Discord user clicks the bookmark.
  • October 2023 (day approximate): SlowMist reports a fake-journalist campaign against friend.tech KOLs in which victims saved malicious JavaScript to target account password/2FA and Privy embedded-wallet tokens.
  • SlowMist publishes 'Threat Intelligence Analysis of a Malicious Bookmark Phishing Attack Targeting FOMO Users' on Medium (body not retrievable by this pipeline: HTTP 403).
  • PANews, ChainCatcher, Phemex, TokenPost, KuCoin and Coinfomania relay the alert; none publish phishing domains, script code, wallet addresses or loss figures.
  • @SlowMist_Team publishes a TI Alert on the campaign, stating it is a familiar technique in a new presentation and that a full analysis will follow.
  • SlowMist's Cos posts on X that bookmark phishing against the FOMO web platform is emerging (fake human verification, drag JavaScript into bookmarks, 2-3 clicks hijack logged-in account).

Sources cited for Malicious Bookmark (Bookmarklet) Phishing Campaign Hijacks

Detection coverage for TL-2026-3041

As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3041 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
6 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats