108 Chrome Extensions Linked to Data Exfiltration and Session Theft via Shared C2 Infrastructure
Blog post from Socket
A coordinated campaign involving 108 malicious Chrome extensions, discovered by Socket's Threat Research Team, has been identified, with these extensions operating under a shared command and control (C2) infrastructure at cloudapi[.]stream. The extensions, published under five different identities, have amassed approximately 20,000 installs from the Chrome Web Store and are capable of stealing credentials, user identities, and browsing data, which are then routed to servers controlled by the campaign's operator. The extensions span various categories, including games and utilities, yet all share a malicious backend that facilitates identity theft, session exfiltration, and unauthorized actions in users' browsers. Notably, the Telegram Multi-account extension exfiltrates active Telegram Web sessions every 15 seconds, allowing for full account takeover without user knowledge. The campaign also features a universal backdoor present in 45 extensions, which opens arbitrary URLs on browser start, and employs tactics such as stripping security headers from target sites to enable further malicious activities. The infrastructure supporting this operation is believed to be a Malware-as-a-Service platform, providing stolen information to buyers, and is linked to a single operator despite the appearance of multiple publisher names. Efforts to remove these extensions have been initiated with requests submitted to both the Chrome Web Store security team and Google Safe Browsing.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.