A long-running campaign injecting fake browser update prompts into compromised websites has expanded dramatically, with researchers tracking malicious code on tens of thousands of sites.

Visitors see convincing overlays urging them to install a critical browser update. The downloads deliver banking trojans targeting Windows and Android, capable of overlaying fake login screens on financial apps and intercepting authentication codes.

The campaign compromises sites through stolen CMS credentials and vulnerable plugins, then filters victims by geography and device to maximize fraud yield while evading researchers.

Users are reminded that browsers update themselves silently and never require manual downloads from third-party sites. Site owners are urged to audit plugins and rotate administrative credentials.