Cyber Security News

Malicious Chrome VPN Extensions Installed 1.5 Million Times Hijacks Browser

In a recent cybersecurity revelation, a highly sophisticated cyber attack campaign has emerged, weaving a web of deceit through malicious web extensions cunningly disguised as VPNs. 

ReasonLabs, a cybersecurity firm, has discovered online piracy tactics involving hidden web extensions.

The assailants employed a multifaceted strategy, exploiting the allure of pirated game torrents featuring popular titles such as GTA and Assassin’s Creed as their primary attack vectors.

The focal point of this insidious campaign revolves around the deployment of fake VPN extensions, masquerading as “netPlus” for Chrome users and “netSave/netWin” for Edge enthusiasts. 

Astoundingly, these extensions managed to amass a staggering 1.5 million downloads, catapulting unsuspecting users into a realm of peril.

Source: chrome-stats

The malicious activities orchestrated by these insidious extensions are far-reaching. 

They include hijacking browser activity and web requests, disabling competing cash-back extensions, and surreptitiously installing additional extensions to amplify their manipulation capabilities. 

The potential motives behind this covert operation include collecting user data and injecting intrusive advertisements.

Additional Insights

Delving into the technical intricacies of the attack, the Trojan installer embedded within pirated game torrents employs an innovative registry method for forcefully installing these malevolent extensions. 

Furthermore, these extensions establish communication channels with command-and-control (C2) servers, revealing a disconcerting connection to Russia-based domains upon network analysis.

The ramifications of this cyber onslaught are profound: compromising user privacy, manipulating browsing activity for potential financial gains through cashback manipulation and ad injection, and exposing users to heightened risks of identity theft and other cybercrimes.

Unraveling additional insights, it becomes apparent that the attack campaign specifically targeted Russian-speaking users, employing advanced techniques to circumvent browser security measures. 

Swift action was taken by Google, who promptly removed all identified extensions from the Chrome Web Store, underscoring the imperative role platforms play in safeguarding users against such threats.

Recommendation

In the wake of this revelation, users must exercise caution and refrain from downloading content from unofficial sources, particularly pirated files. 

Essential precautions include the deployment of robust antivirus and anti-malware software equipped with browser protection. 

Users are urged to meticulously review browser extensions before installation, remaining vigilant against potential threats.

The significance of reporting any suspicious activity to relevant authorities cannot be overstated, as collective efforts are essential in combating the ever-evolving landscape of cybercrime. 

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago