Threat Advisory

Malicious Browser Extension Campaign Misusing Fake Ad Blockers for ClickFix Attacks

Threat: Malicious Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A malicious browser extension campaign has been identified that leverages deceptive social engineering to compromise user systems. The operation begins with victims searching for legitimate browser enhancements such as ad blockers and being directed to install a seemingly trustworthy extension available through an official extension marketplace. Once installed, this extension intentionally destabilizes the users browser and prompts bogus security warnings to trick victims into executing further commands that facilitate malware delivery and execution.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A malicious browser extension campaign has been identified that leverages deceptive social engineering to compromise user systems. The operation begins with victims searching for legitimate browser enhancements such as ad blockers and being directed to install a seemingly trustworthy extension available through an official extension marketplace. Once installed, this extension intentionally destabilizes the users browser and prompts bogus security warnings to trick victims into executing further commands that facilitate malware delivery and execution.[emaillocker id="1283"]

The infection begins when users searching for ad‑blocking tools are redirected to a rogue Chrome extension hosted on the official Web Store, giving it a veneer of legitimacy. The malicious extension closely mimics a popular ad blockers codebase but includes additional logic to register with attacker‑controlled infrastructure and track installation events. After an initial delay using browser timers to avoid immediate detection, the extension triggers a denial‑of‑service condition that exhausts browser resources and causes repeated crashes, prompting a fake browser crash warning. Victims are instructed to open the Windows Run dialog and paste a copied command, which executes a PowerShell command that initiates a secondary payload download via a repurposed system utility. On domain‑joined hosts, this leads to installation of a Python‑based RAT that implements encrypted command‑and‑control communication, persistent registry entries, and capabilities for reconnaissance and remote execution. The extension also employs obfuscation, beaconing to typosquatted domains, and delayed payload activation to evade detection and strengthen the infection chain.

It demonstrates how threat actors are blending social engineering with subtle technical mechanisms to evade detection and maximize impact. By impersonating trusted extensions and weaponizing browser instability to coax users into executing harmful commands, attackers create a self-reinforcing infection loop that can compromise both individual and enterprise environments. Defenders should scrutinize browser extension sources, enforce strict extension whitelisting policies, and educate users to never execute unverified commands supplied through unexpected pop-ups.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial Access T1195.002 Supply Chain Compromise Compromise Software Supply Chain
T1566.002 Phishing Spearphishing Link
T1189 Drive-by Compromise
Execution T1059.001 Command and Scripting Interpreter PowerShell
T1204.002 User Execution Malicious File
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
T1176.001 Software Extensions Browser Extensions
Defense Evasion T1027.010 Obfuscated Files or Information Command Obfuscation
T1036.005 Masquerading Match Legitimate Resource Name or Location
Credential Access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Discovery T1082 System Information Discovery
T1016.001 System Network Configuration Discovery Internet Connection Discovery
Command and Control T1071.001 Application Layer Protocol Web Protocols
T1573.002 Encrypted Channel Asymmetric Cryptography
T1105 Ingress Tool Transfer
Impact T1499.003 Endpoint Denial of Service Application Exhaustion Flood

 

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu