Cybersecurity researchers have identified 19 malicious Google Chrome and Microsoft Edge extensions that use sophisticated update tactics to steal cryptocurrency and sensitive user data from unsuspecting victims.
Key Points
- Socket researchers identified 19 malicious extensions, including 14 created by threat actors and five legitimate tools purchased to distribute malware.
- The campaign, tracked as "Superior," has been active since February 2024 and utilizes automatic browser updates to push malicious code to existing users.
- Malicious capabilities include harvesting seed phrases, draining cryptocurrency wallets, and stealing credentials from platforms like Facebook and LinkedIn.
- The "Enable Right Click & Copy" extension, which has approximately 80,000 users, is among the most significant threats identified in the cluster.
- Attackers employ dynamic command-and-control servers to rotate infrastructure, effectively reducing detection risks and enabling targeted data exfiltration.