18 Chrome and Edge extensions contained malware, and 2.3 million users installed them
#1
Information 
Quote:What happens when 18 malicious add-ons were distributed on the Chrome Web Store and Microsoft Edge Add-ons? Chaos! Security researchers at Koi Security have published a report about what happened.

Normally, when we hear about malicious extensions, they are usually the sort of hastily thrown together garbage which does nothing. Not this time, the add-ons involved did what they promised, i.e. if it was a color picker extension, it worked like one. The issue is, these extensions were also Trojan horses, which silently hijacked the browser, and spying on you, while maintaining a backdoor for the hackers. Apparently, these add-ons stayed harmless for years, before they became malicious through a version update.

Koi began investigating an extension called Color Picker, Eyedropper — Geco colorpick, and found that it was merely one of many such malicious add-ons. The researchers say this was a coordinated effort called "The RedDirection campaign". The attackers used a rogue army of 18 malicious sophistically crafted extensions across Chrome and Edge stores, to hijack browsers, and managed to infect 2.3 million users across both browsers. Yikes!

Interestingly, the add-ons were distributed in various categories, like VPN, weather forecasts, YouTube related, etc. Some of them have achieved verified status, or have been promoted as "featured extensions" on both the Chrome Web Store and Microsoft Edge Add-ons store. Each of this malware had its own command and control subdomain, to mask the fact they were operating from the same centralized attack infrastructure.

Continue Reading...
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
K-Lite Codec Pack 19.1.0 / 19.1.1 Update
Changes in 19.1.1 ...harlan4096 — 07:00
Manjaro Linux 25.0.6 Build 250730
Manjaro Linux 25.0...harlan4096 — 06:57
Brave 1.80.125
Release Channel 1....harlan4096 — 06:55
Vivaldi 7.5 Build 3735.58
Vivaldi 7.5 Build ...harlan4096 — 06:54
360 Total Security 11.0.0.1217
1.0.0.1217 Jul 25,...harlan4096 — 06:53

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>