How it works
The email is framed as a software sponsorship, commonly the Opera GX creator team. It says something like "here is our media kit, please follow the brand guidelines for the integration" and attaches the kit. The file is an .exe or .scr with a name built to look like a document: campaign_mediakit.exe, OperaGX_Assets.scr, brand_guidelines.exe. Opening it runs a stealer that targets your browser cookies and Google session.
The pretext works because reviewing brand assets is a normal part of a real deal, so a "kit" attachment feels routine. The difference is that a genuine media kit is a PDF or a shared drive of logos, fonts, and copy. It never needs to execute.
The tell-tale signals
- A media kit or brand-assets pack that arrives as a program
- A document-looking name whose real ending is .exe, .scr, .com, .pif, .msi, .bat, or .cmd
- A well-known software brand emailing from a domain it does not own
- Instruction to open the kit before terms are agreed
What to do
A media kit never needs to run. If a file claiming to be brand assets ends in .exe or .scr, it is malware, so delete it. Ask for the kit as a PDF or a link on the brand's real domain, which for Opera GX is opera.com, and verify the outreach against Opera's published creator program. If you opened the file, isolate the device and run the account recovery steps: new password, revoked sessions, and revoked app access from a clean device.