Hacking

Browser Push Notifications Used as New Phishing and C2 Vector

Published  ·  3 min read
Updated on November 22, 2025

A new command-and-control platform called Matrix Push C2 is giving attackers a fresh way to deliver phishing links and they’re doing it through something most users don’t think twice about: browser notifications.
According to research from BlackFog, Matrix Push C2 is a browser-native and fileless framework that relies entirely on push notifications, fake alerts, and quick redirects to lure victims. There’s no malware drop at the start, no installer, nothing that immediately gives itself away.
The trick begins with social engineering. A user lands on a malicious or compromised website and is prompted to enable browser notifications. Once they click “Allow,” the attacker gets a direct, ongoing line to the victim through the browser’s built-in push system.
From there, the notifications start rolling in warnings about account logins, “urgent” browser updates, security alerts, you name it. They look legitimate, often borrowing branding from major companies. One click on a “Verify” or “Update” button sends the victim straight to a phishing page.
What makes the attack so effective is that it does everything inside the browser. There’s no need for an initial infection, and because browsers are cross-platform, the attack works on Windows, macOS, Linux, and mobile devices alike.
Once a victim opts in to the fake notifications, their browser effectively becomes part of the attacker’s C2 network.
Inside the Matrix Push C2 Platform
Matrix Push C2 isn’t just a technique; it’s a full-blown malware-as-a-service operation. It’s sold in underground forums and Telegram channels with monthly and yearly subscription options, priced from $150 up to $1,500.
The kit includes a web dashboard where criminals can:
1. send push notifications
2. track victims live
3. log which messages get clicks
4. create shortened malicious URLs
5. record installed browser extensions — including crypto wallets
Attackers also get a collection of pre-built templates designed to mimic familiar brands such as Netflix, TikTok, PayPal, MetaMask, and Cloudflare. These templates help make the phishing attempts look authentic with very little effort.
BlackFog researchers note that the entire platform appeared only recently, around early October, and shows no signs of older versions. Everything points to a freshly launched, purpose-built C2 system.
Why It Matters
Once attackers gain this level of influence over a user’s browser, they can slowly escalate. They might continue sending phishing messages to collect credentials, push the user toward installing more persistent malware, or wait for the right moment to exploit the browser itself.
The ultimate goal is the same as always: steal data, drain crypto wallets, or monetize access however possible.
Meanwhile: Velociraptor Misuse Is Growing
Separately, Huntress has reported a notable increase in attacks abusing Velociraptor, a legitimate digital forensics and incident response tool.
In one recent case, attackers gained entry by exploiting a high-severity flaw in Windows Server Update Services (CVE-2025-59287). After breaking in, they deployed Velociraptor to run reconnaissance queries, gather system details, and map out users and running services.
The attack was stopped before it advanced, but it highlights a broader problem:
Threat actors aren’t relying solely on custom malware anymore. They’re blending legitimate security tools with underground C2 kits like Matrix Push C2 to move quietly and efficiently.
As Huntress puts it, Velociraptor won’t be the last dual-use tool that ends up in the wrong hands.

Source:  The Hacker News

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067