A malicious Chrome extension masquerading as GoogleTranslate has been identified, posing a critical risk to users. This extension can steal sensitive browser data and allow threat actors to remotely interact with Chrome windows while keeping their activity out of the victim’s view. The operation begins with a suspected Rust-based malware loader that drops a malicious Chrome extension alongside an AutoIt script, which subsequently deploys the Stealcv2 information-stealing malware.
Once installed, the fraudulent extension collects a broad range of browser-resident data, including browsing history, saved bookmarks, and stored credentials. The extension also provides attackers with a real-time view of Chrome windows and lets them operate websites remotely using mouse clicks and keyboard input.[/subscribe_to_unlock_form]
A malicious Chrome extension masquerading as GoogleTranslate has been identified, posing a critical risk to users. This extension can steal sensitive browser data and allow threat actors to remotely interact with Chrome windows while keeping their activity out of the victim’s view. The operation begins with a suspected Rust-based malware loader that drops a malicious Chrome extension alongside an AutoIt script, which subsequently deploys the Stealcv2 information-stealing malware.
Once installed, the fraudulent extension collects a broad range of browser-resident data, including browsing history, saved bookmarks, and stored credentials. The extension also provides attackers with a real-time view of Chrome windows and lets them operate websites remotely using mouse clicks and keyboard input.[emaillocker id="1283"]
The threat actors have repeatedly abused trusted-looking browser add-ons to gain access to sensitive information; this campaign is particularly concerning due to its ability to conceal interactive fraud. Users should review installed Chrome extensions immediately, remove unfamiliar or unnecessary add-ons, and scrutinize permission requests—particularly broad access to website data.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Credential access | T1003.001 | OS Credential Dumping | LSASS Memory |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Discovery | T1083 | File and Directory Discovery | - |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1567.002 | Exfiltration Over Web Service | Exfiltration to Cloud Storage |
| Impact | T1489 | Service Stop | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Discovery | E1083 | File and Directory Discovery |
| Impact | B0022 | Remote Access |
| Exfiltration | E1020 | Automated Exfiltration |
| Defense Evasion | F0004 | Disable or Evade Security Tools |
| Execution | B0023 | Install Additional Program |
| Command & Control | B0030 | C2 Communication |
| Execution | E1204 | User Execution |
| Discovery | E1082 | System Information Discovery |
The following reports contain further technical details:
[/emaillocker]