膝盖积液挂什么科| 肝阴虚吃什么药| 三代试管是什么意思| 珊瑚色是什么颜色| 烫发对身体有什么危害| 四大才子是什么生肖| 手脚经常发麻是什么原因| 身上很痒是什么原因| 为什么会肌酐高| 小人难防前一句是什么| 占有欲强是什么意思| 三月有什么节日| 抗坏血酸是什么| flair是什么意思| 腿发热是什么原因引起的| 马甲是什么意思?| 北戴河是什么海| 挂红是什么意思| 全国政协常委什么级别| 脾肾两虚吃什么中成药| 什么是人设| 7月15什么星座| mo是什么意思| 什么是口腔溃疡| 为什么短信验证码收不到| 吃什么能立马通大便| 70年属狗的是什么命| 96年五行属什么| 泰迪哼哼唧唧表示什么| 脂肪肝吃什么药好| 膀胱充盈欠佳什么意思| 手腕扭伤挂什么科| 厉兵秣马是什么意思| 神经过敏是什么意思| 拌凉菜需要什么调料| 檀是什么意思| 吃恩替卡韦有什么副作用| zbc什么意思| 被舔下面什么感觉| 两女一杯什么意思| 憩息是什么意思| 十月初七是什么星座| 小孩子发烧吃什么药| 回头是岸是什么意思| 紫苏有什么作用| 11月出生是什么星座| 心火旺吃什么药效果最好| 皮下囊肿挂什么科| 7月14号是什么节日| 升天是什么意思| 梦见香蕉是什么意思| 菊花可以和什么一起泡水喝| 麻雀为什么跳着走| 什么是锆石| 脂肪肝吃什么| 牙根疼是什么原因| 月经前几天是什么期| 屎是黑色的是什么原因| 宁静是什么意思| 肝最怕什么| 掉头发是什么原因男性| 宝宝打嗝是什么原因| 朔字五行属什么| 姨妈发黑量少什么原因| 尿蛋白弱阳性什么意思| 白细胞高吃什么降得快| 尿沉渣红细胞高是什么原因| seiko手表是什么牌子| 胎膜早破是什么原因引起的| 肤色暗黄适合穿什么颜色的衣服| 阿司匹林有什么副作用| kj什么意思| 光是什么结构| 佛心是什么意思| 男人皮肤黑穿什么颜色的衣服好看| 胸部dr是什么| 睾丸炎吃什么药最有效| 鸡枞是什么| 什么洗面奶好| 口咸是什么原因引起的| 老上火是什么原因造成的| 女生为什么有喉结| 吃什么药补肾| 胃底腺息肉什么意思| 剖腹产坐月子可以吃什么水果| 肾宝片有什么副作用吗| 39岁属什么| 本命年犯太岁什么意思| 芒果有什么好处和坏处| 黄瓜什么时候种| 玄关什么意思| 子是什么生肖| 什么不导电| 行政工作主要负责什么| pa是什么单位| 早上起床口苦吃什么药| 什么眼霜比较好用| 女人更年期吃什么药| 八月二十五是什么星座| pd是什么金属| 农历十二月是什么月| 乳液是什么| 口唇发绀是什么意思| 什么杀精子最厉害| 李白为什么叫青莲居士| 缺钾吃什么食物| 脖子长痘是什么原因引起的| 9527是什么梗| 茉莉茶叶属于什么茶| 三岁看小七岁看老是什么意思| 前列腺是什么症状| 金银满堂是什么生肖| 为什么有脚气| 鼻子大的男人说明什么| 小儿肠胃炎吃什么药| 灼热感是什么样的感觉| 日本有什么好玩的| 脸上长粉刺是什么原因引起的| 耳朵痒是什么原因引起的| 男人喜欢女人什么| 什么情况啊这是| 肾疼是什么症状| 什么是adhd| 黄芪什么季节喝最好| 香菜炒什么好吃| 菠萝蜜不能和什么一起吃| 海市蜃楼为什么可怕| 痣为什么会越来越多| 阳光是什么颜色| 双鱼座是什么星象| 为什么会有黑眼圈| 观是什么意思| 什么硬币最值钱| 八月十五是什么星座| 总是口腔溃疡是什么原因| 尿道口流白色液体是什么病| 什么叫贫血| 甲亢不能吃什么食物| 葡萄和什么不能一起吃| 杨幂的公司叫什么名字| 为什么瘦不下来| 股癣用什么药膏最好| 甲状腺双叶回声欠均匀是什么意思| 胃溃疡a2期是什么意思| 吃什么清肺| 丝苗米是什么米| 新生儿为什么有黄疸| 夜排是什么意思| 头皮屑多用什么洗发水效果好| 5月6日是什么星座| 麦冬长什么样子图片| 血压偏高吃什么药| haglofs是什么牌子| 社保卡是干什么用的| 少字加一笔是什么字| 全职太太是什么意思| 肚子饿了为什么会叫| 脑供血不足是什么原因引起的| 口红什么牌子最好| 特勤是干什么的| 停休是什么意思| 三个水念什么| 身披枷锁是什么生肖| 尖牙什么时候换| 平衡是什么意思| 什么叫双开| 假花放在家里有什么忌讳| 女性失眠吃什么药最好| 口蜜什么剑| 3.1415926是什么意思| 亚撒西是什么意思| 什么生机| 10月13是什么星座| 什么水果不能上供| 结婚送什么| 有偿什么意思| 盆腔炎用什么药好| 女性分泌物少是什么原因| 脉弦是什么意思| 晚上血压高是什么原因| 嗜酸性气道炎症是什么意思| 肚脐右侧是什么器官| 用酒擦身体有什么好处| 荨麻疹去药店买什么药| 东北易帜是什么意思| 大山羊是什么病| 温州冬至吃什么| visa是什么| 蜘蛛吃什么食物| 重日是什么意思| 孩子睡觉咬牙齿是什么原因引起的| 痔疮有什么影响| 维生素e的功效与作用是什么| 什么人不适合去高原| 湿气重不能吃什么| 四月27日是什么星座| 束手无策是什么意思| 流汗有什么好处| 为什么来姨妈左侧输卵管会痛| 有志什么成| few是什么意思| 鼻中隔偏曲是什么意思| 脉数是什么意思| 堞是什么意思| 嘴唇舌头发麻什么病兆| bpo是什么意思啊| 什么东西能缓解孕吐| 胃胀挂什么科| 事物指的是什么| 脓毒血症是什么病| 甲亢不能吃什么食物| 体外射精是什么意思| 天蓝色是什么颜色| 伽蓝菩萨保佑什么| 鄙人什么意思| 1959年属什么| 缘木求鱼什么意思| 眩晕是什么症状| 排卵期是指什么时候| 雪碧喝多了有什么害处| 男士补肾吃什么| 为什么一到晚上就咳嗽| 身上无力是什么原因| o型血的人是什么性格| 火乐读什么| 吃钙片有什么好处| 乳腺结节不能吃什么| 头晕目赤是什么意思| 靖国神社是什么| 吉祥是什么生肖| 被蜜蜂蛰了擦什么药| 拔智齿当天可以吃什么| 什么河水| 风疹病毒是什么意思| cro公司是什么意思| 什么是孢子粉| 瓜子脸适合什么刘海| 白玫瑰花语是什么意思| 腱鞘炎吃什么药| 霉菌感染什么症状| 叫床什么意思| 后背不舒服是什么原因| 备孕吃什么| 竖心旁的字与什么有关| 腿肿应该挂什么科| 脑血管痉挛吃什么药| 矿泉水敷脸有什么作用| 前列腺有什么症状| 脱发严重应该去医院挂什么科| mommy什么意思| 为什么叫中日友好医院| 大腿肌肉酸痛是什么病| 8月9号是什么星座| 肠系膜淋巴结是什么病| 车前草长什么样子| 青海有什么湖| 棱是什么| 什么的天空填合适的词| 6.8什么星座| 肝胆胰腺属于什么科| 喉咙上火吃什么药| 疾病是什么意思| 积劳成疾的疾是什么意思| 吃什么东西能通便| 百度

海南省交通运输厅关于2015年12月份重点公路建设项...

Martin Brinkmann
May 11, 2018
Google Chrome
|
12

A report by security company Radware suggests that Google Chrome users were exposed to yet another wave of malicious extensions offered to them on the official Chrome Web Store.

The extensions were used to perform "credential theft, cryptoming, click fraud, and more" according to Radware.

The company detected the family of new malware for Google Chrome with the help of machine-learning algorithms which it ran on a customer's computer network.

Security firm ICEBRG identified another set of malicious Chrome extensions earlier this year, and 2018 was also the year that extensions with Session Replay functionality appeared in the Store.

Another wave of malicious Chrome extensions detected

chrome malware
screenshot by Radware

According to Radware's analysis, the malware has been active since at least March 2018. It infected more than 100,000 user devices in over 100 countries, and pushed at least seven different Chrome extensions with malicious content using the following attack vector:

  • The attackers use Facebook advertisement to reach potential victims.
  • Users are redirected to fake YouTube pages.
  • A prompt is displayed asking them to install a Chrome extension to play the video.
  • The click on "add extension" installs the extension and makes the user part of the botnet.
  • The malicious JavaScript is executed on installation which downloads additional code from a command center.

The extensions that the attackers used were copies of popular Chrome extensions with malicious, obfuscated code, added to them.

Radware identified the following extensions:

  • Nigelify
  • PwnerLike
  • Alt-j
  • Fix-case
  • Divinity 2 Original Sin: Wiki Skill Popup
  • keeprivate
  • iHabno

You can check the company blog for extension IDs and other information. Google removed all of them in the meantime.

The malware has multiple purposes:

  • Steal Facebook account data by sending Facebook login cookies or Instagram cookies to the command center.
  • Create a Facebook API token if signed in to Facebook and steal it as well.
  • Spread the malware through Facebook using the user's friends network. This happens either as messages in Facebook Messenger or new Facebook posts that uses contact name tags.
  • Mine cryptocurrency using the user's browser. The malware could mine three different coins (Monero, Bytecoin, and Electroneum).

The attackers created several protective measures to prevent users from interfering with the operation.

  • It monitored Chrome's extensions management page and closed it whenever the user tried to open it.
  • Prevents access to cleanup tools on Facebook and in Chrome, and it tried to prevent users from editing or deleting posts, or making comments.
  • Use the browser to watch or like YouTube videos, or write comments.

Closing Words

The identification of the malware happened by accident. Radware's machine-learning algorithm detected the malware and that led to the identification of the network and the removal from the Google Chrome Store.

Considering that the attackers operated the extensions as early as March 2018, it is clear -- again -- that Google's protective system does not work properly.

Chrome users need to verify any extension before they hit the install button. A rule of thumb is that you should never install extensions that prompt you to do so outside of the Chrome Web Store but since malicious extensions are always hosted in the Store, it is not a 100% safeguard against these.

The main issue here is that the majority of users can't verify if a Chrome extension is legitimate or not as it requires analyzing its code.

This leaves running Chrome without extensions as the only option to stay safe.

Now You: do you run Chrome extensions? Do you verify them before installation?

Summary
Google's bad track record of malicious Chrome extensions continues
Article Name
Google's bad track record of malicious Chrome extensions continues
Description
A report by security company Radware suggests that Google Chrome users were exposed to yet another wave of malicious extensions offered to them on the official Chrome Web Store.
Author
Publisher
Ghacks Technology News
Logo
Advertisement

Previous Post: «
Next Post: «

Comments

  1. Christopher Lee Tingen said on December 30, 2021 at 9:01 pm
    Reply

    government and public accesest yo my account done by government will pay for there damage pne way ir another

  2. AAA said on May 12, 2018 at 12:56 pm
    Reply

    Our Lucy is getting very loosey — we must save this Lucy before it becomes a dust mosey e???

  3. Anonymous said on May 12, 2018 at 7:00 am
    Reply

    This has nothing to do with the technology behind it. Google just doesn’t properly vet extensions. The same indiligence with XUL extensions would have your entire web browser under control.

  4. Wayfarer said on May 12, 2018 at 1:06 am
    Reply

    FFS – it’s Google !!!!!!!

    Was any sensible person expecting otherwise ??!!

    We use this stuff because it’s there and there’s usually little other choice.

    But how long has it been since ANY user with two brain cells connected had the SLIGHTEST confidence in “Google-approved” products – either in Chrome or Android?

  5. Sebas said on May 11, 2018 at 6:01 pm
    Reply

    Only reputable addons like Web Api Manager, and UBO, and one I have some questions about: Malwarebytes Browser Extension BETA. But that is only used for a general Google Chrome profile, never for my shopping and login profiles.

    It seems to stop a lot of trackers/ malware, but being from Mbam, privacy could well be compromised. I will however read and implement your article about verifying. Thanks for a useful reminder.

  6. 11r20 said on May 11, 2018 at 5:54 pm
    Reply

    The brainwashed Google lucy’s have always
    come up with solutions after creating the problems in the first place.

    Problem,reaction,solution.

    That’s how these crazed, doped up on LSD Mountain View Ca. lucy’s roll…And since they receive U.S. goobermint fiat for their covert data collection/spy services and censorship duties…the google lucy’s are and always will be above the law.

  7. beemeup5 said on May 11, 2018 at 3:55 pm
    Reply

    WebExtensions will be more like Chrome extensions. They’ll be more secure!

    Yeaaah NO.

  8. ULBoom said on May 11, 2018 at 2:52 pm
    Reply

    I use three extensions in Chromium, they add simple features that should be there but aren’t. An easy to use zoom, cache cleaner and new tab homepage thing. It took hours to find these after rejecting many, many poorly functioning data collection sham extensions with 10^50 fake five star ratings. I do verify what extensions do but why trust anything in the chrome store when chrome is just a browser based ad server?

    Once or twice I’ve seen an opt out FF install bundled with other software but chrome opt outs are hidden everywhere; then there’s the whole android phone universe. With all the volunteers out there doing QA on large companies’ software, google, ms, etc., have no reason to rigorously vet these malicious extensions if their ad business isn’t hurt by them. They get away with cursory checks. Periodically, google announces a clamp down on malware so they appear diligent but malware continues.

  9. ua19 said on May 11, 2018 at 11:21 am
    Reply

    Password generator
    chrome://flags/#enable-password-generation
    chrome://flags/#enable-manual-password-generation

    Bookmarks sync
    Just sign in chrome and sync bookmarks, settings, passwords,… for all your devices

  10. AAA said on May 11, 2018 at 8:34 am
    Reply

    Poor Google baby…. been tackling with the malicious extensions for so long!!!
    How about build and five majority of the users what they actually seek in a browser:
    – Ad block / Tracking protection
    -Bookmarks sync
    -Password generator
    -Secure VPN
    -Cinema / nightmode.

    Rather than working on converting a mere browser into an OS. e???

  11. Nik said on May 11, 2018 at 7:34 am
    Reply

    I am not getting ads even though I have whitelisted you in Ublock Origin in Firefox. Works fine in Chrome.

    1. Richard Allen said on May 11, 2018 at 2:36 pm
      Reply

      If you have uBO disabled and are still not seeing ads I would think some other type of content blocking is still being used.

      FF Tracking Protection for instance will actually block virtually all ads. Not that I’ve spent a lot of time using Tracking Protection by itself but I am yet to see an ad when it is the only active content blocker. Any other type of tracking protection will also block most if not all ads, Ghostery is one example. Ads and tracking are so intertwined nowadays that it is hard to block one without inadvertently blocking the other. Oh well! :)

      If you still see ads when using Chrome and gHacks is whitelisted, that rules out system wide blocking like with a hosts file. So it has to be something in your FF configurationa€| addons, javascript not enabled, and so forth.

Leave a Reply

Check the box to consent to your data being stored in line with the guidelines set out in our privacy policy

We love comments and welcome thoughtful and civilized discussion. Rudeness and personal attacks will not be tolerated. Please stay on-topic.
Please note that your comment may not appear immediately after you post it.