Executive Summary
In November 2025, a sophisticated phishing campaign was uncovered utilizing a novel command-and-control (C2) platform called Matrix Push C2. The threat actors exploited browser push notifications, fake alerts, and fileless redirection to lure users across multiple operating systems into interacting with malicious links. Researchers observed that the campaign delivered phishing payloads without traditional downloads, thereby evading many endpoint defenses and expanding its cross-platform reach. Impacted organizations reported heightened risks of credential theft, business email compromise, and data exfiltration stemming from the hard-to-detect, browser-native behavior of Matrix Push C2.
This incident highlights the escalating threat of fileless attacks and creative social engineering, particularly as businesses increasingly rely on browser-based workflows. The abuse of browser notifications as a phishing vector presents a growing challenge for security teams and underscores the importance of proactive browser and endpoint defenses.
Why This Matters Now
The rapid adoption of browser-based technologies and cross-platform workflows has created new attack surfaces that traditional security tools often overlook. Matrix Push C2 exemplifies how adversaries are innovating to bypass existing prevention and detection controls, making it urgent for organizations to adapt security strategies to defend against fileless, browser-based phishing threats.
Attack Path Analysis
Attackers initiated the campaign by tricking users into clicking malicious browser push notifications, leading to initial compromise through phishing. After establishing access, they may have escalated privileges by abusing web session tokens or browser permissions. The adversaries could then attempt lateral movement across cloud services or browser-integrated SaaS, leveraging persistent access. Command and Control was maintained filelessly via the Matrix Push C2 platform through outbound browser communications. Data exfiltration likely occurred through covert browser channels or stealthy outbound traffic. Finally, the attack could culminate in further phishing propagation, data theft, or account abuse, impacting victim organizations.
Kill Chain Progression
Initial Compromise
Description
Victims received deceptive browser push notifications leading them to malicious links, resulting in account or session compromise via phishing.
Related CVEs
CVE-2025-14020
CVSS 7.5A UI spoofing vulnerability in the LINE client for Android allows attackers to conduct phishing attacks by impersonating legitimate interfaces.
Affected Products:
LINE Corporation LINE – < 14.20
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Phishing: Spearphishing via Link
User Execution: Malicious Fileless Content
Drive-by Compromise
Application Layer Protocol: Web Protocols
Input Capture: Web Portal Capture
System Script Proxy Execution
Multi-Factor Authentication Interception
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Phishing and Social Engineering Defense
Control ID: 5.2.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Systems Security—Monitoring
Control ID: Art. 9(2)d
NIS2 Directive – Incident Handling and Mitigation
Control ID: Art. 21(2)d
CISA ZTMM 2.0 – User and Device Identity Protections
Control ID: Identity Pillar: Phishing and Social Engineering Protections
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Browser-based phishing attacks targeting financial credentials pose severe risks, requiring enhanced egress security and zero trust segmentation for customer protection.
Health Care / Life Sciences
Cross-platform fileless attacks threaten patient data systems, demanding robust threat detection and encrypted traffic controls per HIPAA compliance requirements.
Information Technology/IT
Matrix Push C2's browser notification exploitation requires comprehensive multicloud visibility and anomaly detection across distributed IT infrastructure environments.
Government Administration
Fileless phishing campaigns targeting government systems necessitate inline IPS protection and zero trust network segmentation for critical infrastructure security.
Sources
- Matrix Push C2 Uses Browser Notifications for Fileless, Cross-Platform Phishing Attackshttps://thehackernews.com/2025/11/matrix-push-c2-uses-browser.htmlVerified
- Matrix Push C2 abuses browser notifications to deliver phishing and malwarehttps://www.malwarebytes.com/blog/news/2025/11/matrix-push-c2-abuses-browser-notifications-to-deliver-phishing-and-malwareVerified
- New Matrix Push C2 Abuses Push Notifications to Deliver Malwarehttps://www.blackfog.com/new-matrix-push-c2-deliver-malware/Verified
- Cybercriminals Exploit Browser Push Notifications to Deliver Malwarehttps://www.infosecurity-magazine.com/news/browser-push-notifications-deliver/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, east-west controls, and granular egress policy would have constrained account takeover, limited lateral risk, and contained outbound channels exploited by Matrix Push C2. CNSF capabilities provide inline visibility, microsegmentation, and egress enforcement needed to disrupt this fileless, browser-based attack at multiple stages.
Control: Threat Detection & Anomaly Response
Mitigation: Early detection of anomalous browser-based connections and phishing attempts.
Control: Zero Trust Segmentation
Mitigation: Prevents unauthorized privilege escalation and segmentation bypass within cloud environments.
Control: East-West Traffic Security
Mitigation: Blocks unauthorized lateral movement across cloud workloads and internal services.
Control: Egress Security & Policy Enforcement
Mitigation: Denies outbound connections to unauthorized destinations, disrupting attacker C2.
Control: Cloud Firewall (ACF)
Mitigation: Detects and blocks unauthorized data exfiltration traffic.
Minimizes attack blast radius and reduces operational impact through distributed policy enforcement.
Impact at a Glance
Affected Business Functions
- User Authentication
- System Updates
- Customer Communications
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of user credentials, personal information, and financial data due to phishing attacks facilitated by malicious browser notifications.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Zero Trust segmentation and microsegmentation across all cloud and SaaS-connected workloads to restrict movement post-compromise.
- • Enforce comprehensive egress filtering and FQDN-based controls to block browser-based C2 and exfiltration channels.
- • Implement real-time threat detection to flag anomalous browser notification activity and suspicious outbound connections.
- • Increase visibility into internal east-west flows to detect and contain lateral movement attempts from compromised sessions.
- • Leverage distributed security fabric for rapid incident response and containment, minimizing business impact of fileless browser-based attacks.



