Suspected Russian nation-state threat groups have duped multiple victims into granting potentially persistent access to networks via authentication requests and valid tokens.
Researchers say the hacking group is getting better at finding ways to leverage faults in Javascript to hide and carry out breaches of credit card payment systems.