18 Chrome and Edge extensions contained malware, and 2.3 million users installed them
#1
Information 
Quote:What happens when 18 malicious add-ons were distributed on the Chrome Web Store and Microsoft Edge Add-ons? Chaos! Security researchers at Koi Security have published a report about what happened.

Normally, when we hear about malicious extensions, they are usually the sort of hastily thrown together garbage which does nothing. Not this time, the add-ons involved did what they promised, i.e. if it was a color picker extension, it worked like one. The issue is, these extensions were also Trojan horses, which silently hijacked the browser, and spying on you, while maintaining a backdoor for the hackers. Apparently, these add-ons stayed harmless for years, before they became malicious through a version update.

Koi began investigating an extension called Color Picker, Eyedropper — Geco colorpick, and found that it was merely one of many such malicious add-ons. The researchers say this was a coordinated effort called "The RedDirection campaign". The attackers used a rogue army of 18 malicious sophistically crafted extensions across Chrome and Edge stores, to hijack browsers, and managed to infect 2.3 million users across both browsers. Yikes!

Interestingly, the add-ons were distributed in various categories, like VPN, weather forecasts, YouTube related, etc. Some of them have achieved verified status, or have been promoted as "featured extensions" on both the Chrome Web Store and Microsoft Edge Add-ons store. Each of this malware had its own command and control subdomain, to mask the fact they were operating from the same centralized attack infrastructure.

Continue Reading...
Reply


Messages In This Thread
18 Chrome and Edge extensions contained malware, and 2.3 million users installed them - by harlan4096 - 10 July 25, 09:17

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
K-Lite Codec Pack 19.0.5 / 19.0.8 Update
Changes in 19.0.8 ...harlan4096 — 06:58
Manjaro Linux 25.0.5 Build 250713
Manjaro Linux 25.0...harlan4096 — 06:56
If Google disabled uBlock Origin in Chro...
So, Google went ah...harlan4096 — 06:55
Surfshark VPN : Award-winning VPN servi...
Can your ISP see y...jasonX — 03:34
Surfshark VPN : Award-winning VPN servi...
IKEv2 VPN Explaine...jasonX — 12:23

[-]
Birthdays
Today's Birthdays
avatar (45)RidgeDimb
Upcoming Birthdays
avatar (42)lapedDow
avatar (48)rituabew
avatar (36)omyjul
avatar (40)papedDow
avatar (49)ArnoldFum
avatar (37)yfaza
avatar (48)Kevensi
avatar (38)boineDon
avatar (39)Grompelbawn
avatar (40)vkseogaF
avatar (36)usogy
avatar (39)ywixazok
avatar (37)ixoqe
avatar (35)pa.OpenTran

[-]
Online Staff
There are no staff members currently online.

>