News

Once opened in a browser, the code decrypts a secondary payload using a static XOR key and then redirects the user to an attacker-controlled site via the window.location.href function. These URLs ...
It found 'reasonable assurance' that the VPN provider doesn't log user activity.