How it works

The email is framed as a software sponsorship, commonly the Opera GX creator team. It says something like "here is our media kit, please follow the brand guidelines for the integration" and attaches the kit. The file is an .exe or .scr with a name built to look like a document: campaign_mediakit.exe, OperaGX_Assets.scr, brand_guidelines.exe. Opening it runs a stealer that targets your browser cookies and Google session.

The pretext works because reviewing brand assets is a normal part of a real deal, so a "kit" attachment feels routine. The difference is that a genuine media kit is a PDF or a shared drive of logos, fonts, and copy. It never needs to execute.

The tell-tale signals

What to do

A media kit never needs to run. If a file claiming to be brand assets ends in .exe or .scr, it is malware, so delete it. Ask for the kit as a PDF or a link on the brand's real domain, which for Opera GX is opera.com, and verify the outreach against Opera's published creator program. If you opened the file, isolate the device and run the account recovery steps: new password, revoked sessions, and revoked app access from a clean device.