• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / News / Malicious extensions to the Chrome Web Store

Malicious extensions to the Chrome Web Store

12/05/2018 20:55 by Dimitris

A report by security company Radware shows that Google Chrome users have been exposed to yet another wave of malicious extensions offered by the official Chrome Web Store.

copied extension - Malicious extensions in the Chrome Web Store

Η Radware company reports that these extensions were used to execute "credential theft, encryption, click fraud and more". According to Radware analysis, the malware they discovered was active at least as of March 2018. It has infected more than 100.000 user devices in more than 100 countries and has installed at least seven other different Chrome extensions with malicious content, using following attack method:

1. Attackers use Facebook advertising to reach potential victims.
2. Users are redirected to fake YouTube pages.
3. A question appears asking them to install a Chrome extension to play the video.
4. Clicking on "add extension" installs the extension and makes the user part of a botnet.
5. Malicious JavaScript runs during installation, which installs additional code from a command center.

The extensions used by the attackers were copies of various popular extensions of Chrome, with a similar name, but which contained additional malicious code within them. According to Radware's research, the following extensions (not the same but copies of them) have been identified as malicious:

Nigelify
PwnerLike
Alt-j
Fixed-case
Divinity 2 Original Sin: Wiki Skill Popup
keeprivate
iHabno

copied extension - Malicious extensions in the Chrome Web Store

In the photo above the left extension is the normal one and the right one is the malicious one.

You can check the company website for extension IDs as well as other information. Google has already removed all of these copy-extensions.

known extensions - Malicious extensions in the Chrome Web Store

Considering that the attackers have been operating the extensions since March 2018, it is clear - again - that Google's protection system is not working properly.

Chrome users should verify any extensions they are interested in before deciding to click the install button. One rule of thumb is that you should never install extensions that ask you to do this outside of the Chrome Web Store, but because as you can see there are malicious extensions hosted on the Store, this rule is not a panacea.

The main problem is that the majority of users can not check whether a Chrome extension is legal or not, as to be absolutely sure you need to analyze its code.

Malicious extensions to the Chrome Web Store was last modified: 12 May, 2018, 8: 55 mm by Dimitris

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: Newstag: 2018, botnet, homes, extension, I'm sure

You May Also Like

Do you have anything to post? Send it to Your Post
The 9 best extensions to make Facebook better
Microsoft dropped 94% of the Trickbot botnet

About Us Dimitris

Dimitris hates on Mondays .....

Previous Post: « iGuRu Which antivirus programs delay your computer
Next Post: GDPR all for the General Data Protection Regulation iGuRu »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.