Threat Advisory

Chrome Extension Steals Browser Data and Allows Remote Control

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A malicious Chrome extension masquerading as GoogleTranslate has been identified, posing a critical risk to users. This extension can steal sensitive browser data and allow threat actors to remotely interact with Chrome windows while keeping their activity out of the victim’s view. The operation begins with a suspected Rust-based malware loader that drops a malicious Chrome extension alongside an AutoIt script, which subsequently deploys the Stealcv2 information-stealing malware.

Once installed, the fraudulent extension collects a broad range of browser-resident data, including browsing history, saved bookmarks, and stored credentials. The extension also provides attackers with a real-time view of Chrome windows and lets them operate websites remotely using mouse clicks and keyboard input.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A malicious Chrome extension masquerading as GoogleTranslate has been identified, posing a critical risk to users. This extension can steal sensitive browser data and allow threat actors to remotely interact with Chrome windows while keeping their activity out of the victim’s view. The operation begins with a suspected Rust-based malware loader that drops a malicious Chrome extension alongside an AutoIt script, which subsequently deploys the Stealcv2 information-stealing malware.

Once installed, the fraudulent extension collects a broad range of browser-resident data, including browsing history, saved bookmarks, and stored credentials. The extension also provides attackers with a real-time view of Chrome windows and lets them operate websites remotely using mouse clicks and keyboard input.[emaillocker id="1283"]

The threat actors have repeatedly abused trusted-looking browser add-ons to gain access to sensitive information; this campaign is particularly concerning due to its ability to conceal interactive fraud. Users should review installed Chrome extensions immediately, remove unfamiliar or unnecessary add-ons, and scrutinize permission requests—particularly broad access to website data.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Persistence T1543.003 Create or Modify System Process Windows Service
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Credential access T1003.001 OS Credential Dumping LSASS Memory
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Discovery T1083 File and Directory Discovery -
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1567.002 Exfiltration Over Web Service Exfiltration to Cloud Storage
Impact T1489 Service Stop -

MBC MAPPING:

Objective Behavior ID Behavior
Discovery E1083 File and Directory Discovery
Impact B0022 Remote Access
Exfiltration E1020 Automated Exfiltration
Defense Evasion F0004 Disable or Evade Security Tools
Execution B0023 Install Additional Program
Command & Control B0030 C2 Communication
Execution E1204 User Execution
Discovery E1082 System Information Discovery

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu