Cyber Security

Beware Of Malicious Chrome Extension That Delivers Weaponized ZIP Archive

Malicious Chrome extensions pose significant risks to users, as they can compromise personal information, inject unwanted promotions, and even manipulate web traffic as well.

There are several malicious extensions that remain undetected for extended periods, and this primarily happens due to inadequate moderation by the Chrome Web Store.

eSentire’s Threat Response Unit (TRU) researchers recently identified a malicious Chrome extension that delivers weaponized ZIP archives.

Malicious Chrome Extension

eSentire’s Threat Response Unit discovered a sophisticated malware attack in August 2024,  and this malware attack involved two malicious elements, a LummaC2 stealer and a malicious Google Chrome extension.

The attack began with a drive-by download of a malicious ZIP file that is named “x64x32installer___.zip”, and this malicious ZIP file contains an MSI file.

Decoding Compliance: What CISOs Need to Know – Join Free Webinar

To obtain a password, this file establishes communication with a server at “get-license2[.]com,” and then the obtained password is used by threat actors to extract the malicious DLL called “rnp.dll.”

Now here at this point to load the malicious DLL, threat actors used DLL side-loading using a legit program which is part of OpenPGP cryptographic tools, “rnpkeys.exe.”

This process led to the deployment of the LummaC2 stealer and a PowerShell command. These two elements help in retrieving and decrypting the additional payload from “two-root[.]com.”

The final stage involved installing a malicious Chrome extension named “Save to Google Drive”, which could interact with cryptocurrency accounts on platforms like Facebook, Coinbase, and Google Pay, eSentire added.

Malicious Chrome extension (Source – eSentire)

This extension had capabilities to manipulate account balances, potentially execute transactions, and collect extensive system and browser information, including:- 

  • Hardware details
  • Installed extensions
  • Cookies
  • A unique device identifier

All gathered data was then transmitted to a command and control (C2) server.

Using the “getInjections” function, a browser extension created with malicious purposes was found that changes Native browser functionalities.

It opens popups fairly concealed from the user’s view to follow some URLs such as payments.google, consent.youtube.com, accounts.google.com and adsmanager.facebook.com.

The extension works well with email providers such as Outlook, Gmail, and Yahoo Mail where configuration from chrome.storage.local is injected into web pages and changes the content.

Since it is able to change the mail content, so, due to this ability it may grab two-factor authentication codes as well.

Integration is with CursedChrome, also considered to be an implant that converts compromised browsers into HTTP proxies for the perpetrator to surf as the victim .

Besides this, it also sends tab screenshots to the C2 server with the help of the “makeScreenShot” function.

The C2 addresses are encoded and then used as Base58 from the URLs of the mempool and blockchains in relation to a certain bitcoin address “bc1qvkvzfla6wrem2uf4ejkuja8yp3c6f3xf72kyc9.”

This attack chain executes through the loader using the DLL side loading to deploy the LummaC2 stealer and the malicious extension.

In response to this, a 24/7 SOC team isolated the infected host and assisted with remediation.

Recommendations

Here below we have mentioned all the recommendations:-

  • Secure devices with EDR solutions.
  • Provide phishing awareness training.
  • Educate on emerging threats.
  • Set script files to open in Notepad.
  • Prevent automatic script execution.

IoCs

C2s:

http://run-df[.]com/gAySB.php?cnv_id=false&value=1
http://hit-1488.com/test_gate0117[.]php?a=XyLGVaXA1cIfBjj&id=0
get-license2[.]com
publicitttyps[.]shop
true-lie[.]com
true-bottom[.]com
two-root[.]com

Download Free Incident Response Plan Template for Your Security Team – Free Download

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago