EXECUTIVE SUMMARY:
A malicious browser extension campaign has been identified that leverages deceptive social engineering to compromise user systems. The operation begins with victims searching for legitimate browser enhancements such as ad blockers and being directed to install a seemingly trustworthy extension available through an official extension marketplace. Once installed, this extension intentionally destabilizes the users browser and prompts bogus security warnings to trick victims into executing further commands that facilitate malware delivery and execution.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A malicious browser extension campaign has been identified that leverages deceptive social engineering to compromise user systems. The operation begins with victims searching for legitimate browser enhancements such as ad blockers and being directed to install a seemingly trustworthy extension available through an official extension marketplace. Once installed, this extension intentionally destabilizes the users browser and prompts bogus security warnings to trick victims into executing further commands that facilitate malware delivery and execution.[emaillocker id="1283"]
The infection begins when users searching for ad‑blocking tools are redirected to a rogue Chrome extension hosted on the official Web Store, giving it a veneer of legitimacy. The malicious extension closely mimics a popular ad blockers codebase but includes additional logic to register with attacker‑controlled infrastructure and track installation events. After an initial delay using browser timers to avoid immediate detection, the extension triggers a denial‑of‑service condition that exhausts browser resources and causes repeated crashes, prompting a fake browser crash warning. Victims are instructed to open the Windows Run dialog and paste a copied command, which executes a PowerShell command that initiates a secondary payload download via a repurposed system utility. On domain‑joined hosts, this leads to installation of a Python‑based RAT that implements encrypted command‑and‑control communication, persistent registry entries, and capabilities for reconnaissance and remote execution. The extension also employs obfuscation, beaconing to typosquatted domains, and delayed payload activation to evade detection and strengthen the infection chain.
It demonstrates how threat actors are blending social engineering with subtle technical mechanisms to evade detection and maximize impact. By impersonating trusted extensions and weaponizing browser instability to coax users into executing harmful commands, attackers create a self-reinforcing infection loop that can compromise both individual and enterprise environments. Defenders should scrutinize browser extension sources, enforce strict extension whitelisting policies, and educate users to never execute unverified commands supplied through unexpected pop-ups.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Initial Access | T1195.002 | Supply Chain Compromise | Compromise Software Supply Chain |
| T1566.002 | Phishing | Spearphishing Link | |
| T1189 | Drive-by Compromise | ||
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| T1204.002 | User Execution | Malicious File | |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| T1176.001 | Software Extensions | Browser Extensions | |
| Defense Evasion | T1027.010 | Obfuscated Files or Information | Command Obfuscation |
| T1036.005 | Masquerading | Match Legitimate Resource Name or Location | |
| Credential Access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Discovery | T1082 | System Information Discovery | |
| T1016.001 | System Network Configuration Discovery | Internet Connection Discovery | |
| Command and Control | T1071.001 | Application Layer Protocol | Web Protocols |
| T1573.002 | Encrypted Channel | Asymmetric Cryptography | |
| T1105 | Ingress Tool Transfer | ||
| Impact | T1499.003 | Endpoint Denial of Service | Application Exhaustion Flood |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]