Attack of The Extensions

Summary

This article details a new technique for establishing persistent access within Chromium browsers using malicious browser extensions. These extensions can transform a browser into a command and control (C2) platform, enabling silent and persistent cookie theft.

IFF Assessment

FOE

The article describes a new attack vector that allows for persistent access and data exfiltration through malicious browser extensions, posing a significant threat to users.

Defender Context

Defenders should be aware of the risks posed by malicious browser extensions, especially in environments using Chromium-based browsers. Monitoring for unusual extension installations and browser behavior, as well as educating users about extension security, are crucial mitigation strategies.

Read Full Story →