Linchakin

Beware of new Malicious Chrome Extension that Delivers Password Stealer Malware

 December 07, 2021     No comments   

Malicious Chrome Extension

Several malvertising campaigns have been discovered recently by the security experts of Cisco Talos. In these malvertising campaigns, it has been detected that the threat actors have been using the fake installers of popular apps and games like:-

  • WeChat
  • Viber
  • Battlefield
  • NoxPlayer

Hackers have been using these fake installers to trick their victims into downloading a malicious Google Chrome extension with a backdoor. 

All these malware families are in constant development and improvement by their developers. And the malware payloads were attributed by the researchers to an unknown actor with “magnat” alias.

The primary objective of the hacker is to steal sensitive data, credentials and maintain remote access to the compromised system.

Pieces of malware

On the victim’s compromised system, the threat actor executes three pieces of malware by running the fake installers, and here they are mentioned below:-

  • An undocumented malicious browser extension.
  • A password stealer.
  • A “backdoor” for setting up remote access.

Malicious campaign

In these malicious campaigns, the operators have used several file types with the names like:-

  • viber-25164.exe
  • wechat-35355.exe
  • build_9.716-6032.exe
  • setup_164335.exe
  • nox_setup_55606.exe
  • battlefieldsetup_76522.exe

Once these files are executed by the victim, these files start executing the malicious loaders on the compromised system of the victim instead of installing the authentic software.

The threat actors use these malvertising campaigns to target the users by presenting them links to download the fake installers on search engines who are searching for popular software.

Like this, they drop three elements:-

  • A password stealer known as RedLine Stealer.
  • A Chrome extension dubbed “MagnatExtension” to record keystrokes and capture screenshots.
  • An AutoIt-based backdoor that builds remote access on the compromised system.

Targets & Campaign timeline

The primary targets of Magnat are the users from the following countries:-

  • The USA
  • Canada
  • Australia
  • Spain
  • Italy
  • Norway

Here is the timeline analyzed by Cisco TALOS:-

The command-and-control (C2) communications of MagnatExtension is outstanding since the C2 address of this extension is hard-coded. But, with the method in which it arranges a new C2 address from a Twitter search for hashtags like “#aquamamba2019” or “#ololo2019” it accumulates a major drawback.

Here’s what Tiago Pereira, one of the Cisco Talos researchers, said:-

“Based on the use of password stealers and a Chrome extension that is similar to a banking trojan, we assess that the attacker’s goals are to obtain user credentials, possibly for sale or for his own use in further exploitation.”

While the threat actors will continue to develop and improve the campaigns like this to steal sensitive data and credentials. So, the experts recommended that users should always use robust security mechanisms and tools to stay safe.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity, and hacking news updates.

Adblock test (Why?)


You may be interested in:
>> Is a Chromebook worth replacing a Windows laptop?
>> Find out in detail the outstanding features of Google Pixel 4a
>> Top 7 best earbuds you should not miss

Related Posts:
>> Recognizing 12 Basic Body Shapes To Choose Better Clothes
>>Ranking the 10 most used smart technology devices
>> Top 5+ Best E-readers: Compact & Convenient Pen
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook

Related Posts:

  • MAMP PRO 6.5 – Create a local server environment for Web development and moreMAMP PRO is the commercial, professional grade version of the classic local server environment for OS X: MAMP. Designed for professional Web developer… Read More
  • HP’s new 34-inch all-in-one PC looks light years ahead of Apple's iMacThe HP Envy 34 AIO can be equipped with the mighty Nvidia GeForce RTX 3080 Powerful all-in-one (AIO) desktop computers are something of a rarity, especially if you want a machine that’ll handle some of the best PC games. Whi… Read More
  • Haklistgen - Turns Any Junk Text Into A Usable Wordlist For Brute-Forcing Turns any junk text into a usable wordlist for brute-forcing. Installation go install github.com/hakluke/[email protected] Usage Examples Scrape al… Read More
  • iPhone 13 — here’s where Android phones still winiPhone 13 is great, but Apple's phones could be even betterThe iPhone 13 is an excellent phone. Actually, according to our global editor in chief Mark Spoonauer, the iPhone 13 Pro Max is the best phone ever ma… Read More
  • Before you use a VPN for Netflix in Canada, Here's what you should know Millennials label Netflix as the paradise for cinephiles & binge-racers because of its huge collection of award-winning movies, shows, documenta… Read More
Newer Post Older Post Home

0 Comments:

Post a Comment


Copyright © 2025 Linchakin | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates