{"id":303743,"date":"2025-11-23T15:47:08","date_gmt":"2025-11-23T15:47:08","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/303743\/"},"modified":"2025-11-23T15:47:08","modified_gmt":"2025-11-23T15:47:08","slug":"netflix-and-paypal-users-warned-as-matrix-hackers-attack","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/303743\/","title":{"rendered":"Netflix And PayPal Users Warned As Matrix Hackers Attack"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2025\/11\/1763912828_582_0x0.jpg\" alt=\"Netflix logo on smartphone, password entry box in image background.\" data-height=\"2488\" data-width=\"3732\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>Matrix attackers target Netflix, PayPal and others.<\/p>\n<p>NurPhoto via Getty Images<\/p>\n<p>It has been a week of \u2018not what they seem\u2019 hack attacks. First there was the news of how cybercriminals are testing out a new Android banking trojan called <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/23\/hackers-bypass-signal-telegram-and-whatsapp-encryption-to-read-messages\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/23\/hackers-bypass-signal-telegram-and-whatsapp-encryption-to-read-messages\/\" target=\"_self\" aria-label=\"Sturnus\" rel=\"nofollow noopener\">Sturnus<\/a> that reads secure instant message conversations by bypassing encryption and copying them when displayed on the smartphone screen. Then, a warning to businesses to avoid falling victim to stealthy <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/18\/copy-and-paste-cybersecurity-warning---99-of-enterprises-now-at-risk\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/18\/copy-and-paste-cybersecurity-warning---99-of-enterprises-now-at-risk\/\" target=\"_self\" aria-label=\"copy-and-paste attacks\" rel=\"nofollow noopener\">copy-and-paste attacks<\/a> using the clipboard as an attack vector. And now, dear reader, it\u2019s the turn of the Matrix. No, not that Matrix, but Matrix Push. This cybercrime platform is using compromised and highly disguised web browser notifications to fool Netflix, PayPal and users of other high-profile services to <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/01\/proton-exposes-300-million-stolen-credentials---49-include-passwords\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/01\/proton-exposes-300-million-stolen-credentials---49-include-passwords\/\" target=\"_self\" aria-label=\"grab account credentials\" rel=\"nofollow noopener\">grab account credentials<\/a>. Here\u2019s what you need to know. <\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/18\/search-this-new-password-hack-list-now---if-you-find-yours-delete-it\/\" target=\"_blank\" aria-label=\"Search This New Password Hack List Now \u2014 If You Find Yours, Delete It\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/18\/search-this-new-password-hack-list-now---if-you-find-yours-delete-it\/\" rel=\"nofollow noopener\">ForbesSearch This New Password Hack List Now \u2014 If You Find Yours, Delete ItBy Davey Winder<\/a>Netflix And PayPal Users Among Those Warned To Beware The Matrix<\/p>\n<p>If there are three cybersecurity-related things I can say with some certainty as we start the fast descent into the new year, then they are as follows:<\/p>\n<p>Phishing is not going anywhere.All operating systems will remain open to threats.Cybercriminals will continue to develop new and effective attack platforms.<\/p>\n<p>I mention this as all three are neatly wrapped up in a new threat warning report that has been issued by BlackFog security, and confirms a new command-and-control platform, <a class=\"color-link\" href=\"https:\/\/www.blackfog.com\/new-matrix-push-c2-deliver-malware\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.blackfog.com\/new-matrix-push-c2-deliver-malware\/\" aria-label=\"Matrix Push C2\">Matrix Push C2<\/a>, being used by cybercriminals to deliver malware and phishing attacks by way of web browser functionality. <\/p>\n<p>Leveraging push browser notifications, faked system alerts, and lick-me link redirects, Matrix Push \u201cturns web browsers into an attack delivery vehicle,\u201d BlackFog\u2019s Brenda Robb said. <\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/10\/hotels-hacker-alert-issued-as-i-paid-twice-attacks-confirmed\/\" target=\"_blank\" aria-label=\"Hotels Hacker Alert Issued As \u2018I Paid Twice\u2019 Attacks Confirmed\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/10\/hotels-hacker-alert-issued-as-i-paid-twice-attacks-confirmed\/\" rel=\"nofollow noopener\">ForbesHotels Hacker Alert Issued As \u2018I Paid Twice\u2019 Attacks ConfirmedBy Davey Winder<\/a><\/p>\n<p>The phishing threat is there from the start, using social engineering to get potential victims to agree to accept browser notifications on a website that may be entirely malicious, or entirely legitimate but unknowingly compromised. Doing so sets off a chain of events that can have disastrous consequences. Browser app web push notifications are exploited by sending carefully crafted alerts that appear to be from the operating system or browser and pretend to be on behalf of the likes of Netflix and PayPal.<\/p>\n<p>\u201cWe found templates for brands such as MetaMask, Netflix, Cloudflare, PayPal, TikTok, and more,\u201d Robb confirmed, \u201ceach designed to look like a legitimate notification or security page from those providers.\u201d<\/p>\n<p>The cunning ploy here is that these notifications appear where you would expect them to, in the genuine notification area of the device, which makes it much more likely the user will accept them as real and respond by clicking through to whatever credential-grabbing resource they will end up at. <\/p>\n<p>Netflix users can get advice regarding phishing attacks <a class=\"color-link\" href=\"https:\/\/help.netflix.com\/en\/node\/65674\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/help.netflix.com\/en\/node\/65674\" aria-label=\"here\">here<\/a>, while PayPal users can find the same <a class=\"color-link\" href=\"https:\/\/www.paypal.com\/uk\/security\/report-suspicious-messages\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.paypal.com\/uk\/security\/report-suspicious-messages\" aria-label=\"here\">here<\/a>.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-3\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/14\/all-microsoft-windows-users-warned-as-new-bot-attacks-confirmed\/\" target=\"_blank\" aria-label=\"All Microsoft Windows Users Warned As New Bot Attacks Confirmed\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/14\/all-microsoft-windows-users-warned-as-new-bot-attacks-confirmed\/\" rel=\"nofollow noopener\">ForbesAll Microsoft Windows Users Warned As New Bot Attacks ConfirmedBy Davey Winder<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Matrix attackers target Netflix, PayPal and others. NurPhoto via Getty Images It has been a week of \u2018not&hellip;\n","protected":false},"author":2,"featured_media":303744,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[64,63,173324,173325,15859,173323,13205,53555,105,128788,101],"class_list":{"0":"post-303743","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-au","9":"tag-australia","10":"tag-blackfog","11":"tag-chrome-browser-compromise","12":"tag-cloudflare","13":"tag-matrix-push","14":"tag-paypal","15":"tag-phishing","16":"tag-technology","17":"tag-the-matrix","18":"tag-tiktok"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/303743","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=303743"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/303743\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/303744"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=303743"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=303743"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=303743"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}