Summary:
The discovery of the malicious Google Chrome extension "ParaSiteSnatcher" reveals a sophisticated cyber threat targeting users in Latin America, particularly Brazil. This framework enables threat actors to monitor, manipulate, and exfiltrate sensitive information from various sources, with a specific focus on Banco do Brasil and Caixa Econômica Federal-related URLs. The extension exploits the Chrome Browser API to intercept and exfiltrate data, including Brazilian Tax ID numbers, Microsoft account cookies, and payment information from systems. ParaSiteSnatcher is designed to work on Chromium-based browsers, expanding its potential impact beyond Google Chrome.[/subscribe_to_unlock_form]
Summary:
The discovery of the malicious Google Chrome extension "ParaSiteSnatcher" reveals a sophisticated cyber threat targeting users in Latin America, particularly Brazil. This framework enables threat actors to monitor, manipulate, and exfiltrate sensitive information from various sources, with a specific focus on Banco do Brasil and Caixa Econômica Federal-related URLs. The extension exploits the Chrome Browser API to intercept and exfiltrate data, including Brazilian Tax ID numbers, Microsoft account cookies, and payment information from systems. ParaSiteSnatcher is designed to work on Chromium-based browsers, expanding its potential impact beyond Google Chrome.[emaillocker id="1283"]
The malware is delivered through a VBScript downloader with three distinct variants, each varying in obfuscation complexity. Once executed, the downloader checks for Chrome installation and specific system paths before communicating with the attacker's Command and Control (C&C) server. The C&C server responds with obfuscated URLs, leading to the download of additional malicious modules, including the extension components. The extension's core components include manifest.json, defining metadata and permissions, yyva.js (Extension Service Worker) for event handling and communication, sovvy.js (content script) for data exfiltration, 33nhauh.js for banking operations, unpgp2.js for interactions with Caixa Econômica Federal, and s12ih0a.js for data monitoring and exfiltration. Together, these components orchestrate a multifaceted attack, emphasizing the threat posed by malicious browser extensions.
ParaSiteSnatcher's detailed analysis underscores the threat posed by malicious browser extensions, emphasizing the need for user vigilance when granting permissions. The extension's ability to target sensitive data, operate stealthily, and persist on systems raises concerns about detection and removal challenges. The multifaceted approach, leveraging Chrome API for communication, monitoring, and data exfiltration, highlights the evolving sophistication of cyber threats. While the primary focus is on Google Chrome, the extension's compatibility with other Chromium-based browsers poses a wider risk, urging users to exercise caution in downloading extensions across various platforms. The case emphasizes the critical role of cybersecurity measures in protecting against increasingly complex threats in the digital landscape.
Threat Profile:

References:
The following reports contain further technical details:
[/emaillocker]