Target Industry

Indiscriminate, opportunistic targeting.

Overview

A new threat involving malicious Chrome and other Chromium-based browser extensions has been discovered. This flaw allows malicious extensions to impersonate other extensions, enabling threat actors to steal sensitive information from users. The attack is called “polymorphic” because the extensions can change their form to avoid detection. This poses a critical security risk for users of major browsers like Chrome and Edge. 

Impact

The impact of this new threat involving polymorphic browser extensions is critical. Malicious extensions can steal sensitive information, such as passwords, financial details, and personal data. Users may lose trust in browser extensions, even legitimate ones, due to the risk of impersonation.  

The ability of these extensions to change form makes them difficult to detect and remove, posing ongoing security risks. Users may even suffer financial losses if their banking or crypto wallet information is compromised.  

Exploitation

The exploitation of polymorphic browser extensions involves several steps. First, the user unknowingly installs a malicious extension, often disguised as a legitimate tool. After it is installed, the extension scans the browser for other installed extensions and changes its appearance to mimic a legitimate one.  

These could be password managers, banking applications, or digital wallets. It may temporarily disable the legitimate extension, tricking users into interacting with the fake one. When users enter their credentials into the fake extension, the information is captured and sent to the threat actor. Stored passwords can be lost with just one click on a malicious prompt. 

Containment, Mitigations & Remediations

To mitigate the threat of polymorphic browser extensions, users should be cautious when installing extensions and only download them from trusted sources. Regularly review and update installed extensions and remove any that are no longer needed. Browser developers should enhance security protocols to detect and block malicious extensions. Additionally, using robust security software can help identify and prevent such threats. Educating users about the risks and signs of malicious extensions is also crucial in reducing the likelihood of exploitation.  

Cyber News reports that there is currently no patch to remedy this vulnerability because it is an inherent function of the Chrome browser. According to cyber security company SquareX, this is not a software problem as no vulnerability exists. 

Threat Landscape

In a recent campaign involving similar malicious extensions at least 300,000 users across Google Chrome and Microsoft Edge were affected. Given the widespread use of these browsers, millions of users could potentially be at risk if such threats continue to evolve and spread. Major browsers like Chrome and Edge are affected, creating a vast attack vector. 

Threat Groups

The specific threat group behind this has not been publicly identified at the time of writing. 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content