墨鱼和鱿鱼有什么区别| 井柏然原名叫什么| 11.9是什么星座| acc是什么意思| 谷丙转氨酶高吃什么药可以降下来| 青蛙为什么晚上叫| 梦见蛇是什么预兆| 清热去湿热颗粒有什么功效| 2024年属龙的是什么命| 什么四海| 主动脉瓣退行性变是什么意思| 晚上7点是什么时辰| 经常咬手指甲是什么原因| 血压高降不下来是什么原因| 三月二十八号是什么星座| 菠萝蜜的核有什么功效| 做人流吃什么水果| 外贸原单是什么意思| 12月11日什么星座| 8000年前是什么朝代| 财星是什么意思| 牛逼什么意思| 为什么很困却睡不着| 肌酐低有什么危害| 二月初九是什么星座| 嗜睡是什么原因| 黑鱼又叫什么鱼| 什么是缓刑意思是什么| 体内湿气重是什么原因造成的| 喝碳酸饮料有什么危害| 七月上旬是什么时候| 男人山根有痣代表什么| 梦到前任预示着什么| 二个月不来月经是什么原因| 从商是什么意思| 磋商是什么意思| 医院查过敏源挂什么科| 头皮癣用什么药膏最好| 毛肚是什么动物身上的| 女人排卵是什么时间| 假体是什么| 装什么病能容易开病假| 土地出让金什么意思| 前方起飞是什么意思| 少叙痣是什么意思| ys是什么意思| 大同有什么好吃的| 烂尾是什么意思| is是什么组织| l读什么| 炎症吃什么消炎药| 朋友圈发女朋友照片配什么文字| 孱弱是什么意思| 运气是什么意思| 彰字五行属什么| 专科学什么专业好就业| 什么是同比| 白痰吃什么药| 985211是什么意思| dc是什么| 强肉弱食是什么意思| 万圣节为什么要送糖果| 三七泡酒有什么功效| 喝酸奶有什么好处| 什么是签注| 艺字五行属什么| 属猴的守护神是什么菩萨| 川崎病是什么症状| 华盖是什么| 3.9是什么星座| 梦见两个小男孩是什么意思| 计抛是什么意思| 308什么意思| 张家界莓茶有什么功效| 福建岩茶属于什么茶| 什么叫越位| 血压忽高忽低是什么原因| 各类病原体dna测定是检查什么| 坐东北朝西南是什么宅| 627是什么星座| 最早的春联是写在什么上面的| 茯砖茶是什么茶| 吃什么可以丰胸| 脑部ct挂什么科| 胳膊疼痛是什么原因| 养流浪猫需要注意什么| 尿毒症前兆是什么症状表现| 凭什么是什么意思| 痔疮是什么样的图片| 血沉是什么| 最大的动物是什么| 右肋骨下方隐隐疼痛是什么原因| 38岁属什么的生肖| 拉肚子不能吃什么食物| 脾湿吃什么中成药| 安全生产职责是什么| bottle什么意思| pcr是什么| 瞎子吃核桃砸了手是什么生肖| 15号是什么日子| 午时是什么时间| 孕早期宫缩是什么感觉| 灰猫是什么品种| 消化不良吃什么水果好| food什么意思| 核桃壳有什么用| 仓鼠是什么科动物| 身份证穿什么衣服| 感冒喉咙痛吃什么药| 郑和是什么族| 农历3月是什么月| 郑州有什么好玩的| 献血有什么好处和坏处| 青蛙趴有什么好处| 吃什么水果对皮肤好| 十月十三是什么星座| 区长什么级别| 甘油三酯高吃什么降得快| 糟卤可以做什么菜| mary是什么意思| 异地办理临时身份证需要什么材料| 铁观音是什么茶| 异质性是什么意思| 小土豆是什么意思| 什么叫裸眼视力| 搬家送什么礼物最好| 男人腰痛吃什么药| 野生天麻长什么样图片| 月经期间适合做什么运动| 甘草泡水喝有什么好处和坏处| 阑尾有什么用| 又拉肚子又呕吐是什么原因| 梅开二度是什么意思| 对牛弹琴告诉我们什么道理| 牙齿遇冷热都痛是什么原因| 镜子是用什么做的| 什么是两栖动物| 副乡长是什么级别| 做飞机需要注意什么| 大便红褐色是什么原因| 1953属什么生肖| 心跳突然加快是什么原因| 为什么会出现眼袋| 为什么同房不怀孕原因| 劳伦拉夫属于什么档次| 情人节送什么给女孩子| 二月二十五号是什么星座| 慢性胃炎吃什么药| 被螨虫咬了非常痒用什么药膏好| 尿毒症是什么症状| 老板喜欢什么样的员工| 七月十五日是什么节日| 缺碘有什么症状| hiv弱阳性是什么意思| 叶酸不能和什么一起吃| 过生日送什么礼物好| 成都有什么特产| 心慌挂什么科| 智商105是什么水平| 身上长白色的斑点是什么原因| 7月份可以种什么菜| 为什么会突发脑溢血| 湿疹涂什么| 勃起不硬吃什么药| 平动是什么意思| 过敏性鼻炎喝什么茶好| 青椒是什么意思| 送老人什么礼物最好| 孤单是什么意思| 东风是什么意思| 血常规检查能查出什么| 什么的落日| 大象是什么颜色| 湿热吃什么食物| pp是什么材料| 女人吃什么养肝排毒| cd ts 什么意思| 奥利奥是什么意思| 画蛇添足告诉我们什么道理| 封建社会是什么意思| 性功能下降吃什么药| 做面条用什么面粉| 肺炎吃什么药| 孔雀开屏寓意什么意思| 硬不起来是什么原因| 微信为什么不能转账| 吃醋是什么意思| 风林火山是什么意思| 分泌物多是什么原因| 慷慨什么意思| o型血和b型血生的孩子是什么血型| 妈妈的奶奶应该叫什么| 今天穿什么衣服合适| k代表什么| 吃什么助于长高| 精神出轨是什么意思| mirage轮胎什么牌子| 梦到自己开车是什么意思| 漂白粉是什么| 湿疹是什么样的图片| 组织是什么意思| 心肌供血不足吃什么药| 单身领养孩子需要什么条件| 艾叶泡水喝有什么功效| 儿童支原体感染吃什么药| 来事头疼什么原因| 不悔梦归处只恨太匆匆是什么意思| 蛇吃什么食物| 一个点是什么字| 牙疼吃什么止疼药| 鱼眼睛吃了有什么好处| coupon是什么意思| hh是什么品牌| 沙中土命什么意思| 孩子出汗多是什么原因| 红薯不能和什么一起吃| 尿液分析是检查什么| 三点水一个希读什么| 预检是什么意思| cancer是什么意思| 玉米是什么时候传入中国的| 嗓子痛什么原因| kys什么意思| 焦是什么意思| 血小板低有什么症状| ofd是什么意思| 133是什么意思| 女人喜欢什么样的阴茎| 为什么晚上不能照镜子| 不寐病属于什么病症| 6月20是什么星座| 人类什么时候出现的| 河虾吃什么| 捐肾对身体有什么影响| 什么叫通勤| 猪狗不如是什么意思| 小孩铅过高有什么症状| 4个火念什么| 车加尿素起什么作用| 肌张力高有什么症状| 扦脚是什么意思| 1926年属什么| iabp医学上是什么意思| 婉甸女装属于什么档次| 嗓子痛挂什么科| 头疼吃什么药| 为什么萤火虫会发光| 什么是雌激素| 红参适合什么人吃| 胸ct和肺ct有什么区别| 什么是cpi| 三下乡是什么| 爱做梦是什么原因应该怎样调理| 药流有什么危害| sunny是什么意思| 检查hpv需要注意什么提前注意什么| 出虚汗吃什么中成药| 石斤读什么| 试管进周期是什么意思| 面粉可以做什么| 外周血是什么意思| 十二指肠胃溃疡吃什么药| 脑回路什么意思| 吃什么不会便秘| 百度

K-Lite Codec Pack Basic(影音解码器)V13.1.0官方版

Martin Brinkmann
May 11, 2018
Google Chrome
|
12

A report by security company Radware suggests that Google Chrome users were exposed to yet another wave of malicious extensions offered to them on the official Chrome Web Store.

The extensions were used to perform "credential theft, cryptoming, click fraud, and more" according to Radware.

The company detected the family of new malware for Google Chrome with the help of machine-learning algorithms which it ran on a customer's computer network.

Security firm ICEBRG identified another set of malicious Chrome extensions earlier this year, and 2018 was also the year that extensions with Session Replay functionality appeared in the Store.

Another wave of malicious Chrome extensions detected

chrome malware
screenshot by Radware

According to Radware's analysis, the malware has been active since at least March 2018. It infected more than 100,000 user devices in over 100 countries, and pushed at least seven different Chrome extensions with malicious content using the following attack vector:

  • The attackers use Facebook advertisement to reach potential victims.
  • Users are redirected to fake YouTube pages.
  • A prompt is displayed asking them to install a Chrome extension to play the video.
  • The click on "add extension" installs the extension and makes the user part of the botnet.
  • The malicious JavaScript is executed on installation which downloads additional code from a command center.

The extensions that the attackers used were copies of popular Chrome extensions with malicious, obfuscated code, added to them.

Radware identified the following extensions:

  • Nigelify
  • PwnerLike
  • Alt-j
  • Fix-case
  • Divinity 2 Original Sin: Wiki Skill Popup
  • keeprivate
  • iHabno

You can check the company blog for extension IDs and other information. Google removed all of them in the meantime.

The malware has multiple purposes:

  • Steal Facebook account data by sending Facebook login cookies or Instagram cookies to the command center.
  • Create a Facebook API token if signed in to Facebook and steal it as well.
  • Spread the malware through Facebook using the user's friends network. This happens either as messages in Facebook Messenger or new Facebook posts that uses contact name tags.
  • Mine cryptocurrency using the user's browser. The malware could mine three different coins (Monero, Bytecoin, and Electroneum).

The attackers created several protective measures to prevent users from interfering with the operation.

  • It monitored Chrome's extensions management page and closed it whenever the user tried to open it.
  • Prevents access to cleanup tools on Facebook and in Chrome, and it tried to prevent users from editing or deleting posts, or making comments.
  • Use the browser to watch or like YouTube videos, or write comments.

Closing Words

The identification of the malware happened by accident. Radware's machine-learning algorithm detected the malware and that led to the identification of the network and the removal from the Google Chrome Store.

Considering that the attackers operated the extensions as early as March 2018, it is clear -- again -- that Google's protective system does not work properly.

Chrome users need to verify any extension before they hit the install button. A rule of thumb is that you should never install extensions that prompt you to do so outside of the Chrome Web Store but since malicious extensions are always hosted in the Store, it is not a 100% safeguard against these.

The main issue here is that the majority of users can't verify if a Chrome extension is legitimate or not as it requires analyzing its code.

This leaves running Chrome without extensions as the only option to stay safe.

Now You: do you run Chrome extensions? Do you verify them before installation?

Summary
Google's bad track record of malicious Chrome extensions continues
Article Name
Google's bad track record of malicious Chrome extensions continues
Description
A report by security company Radware suggests that Google Chrome users were exposed to yet another wave of malicious extensions offered to them on the official Chrome Web Store.
Author
Publisher
Ghacks Technology News
Logo
Advertisement

Previous Post: «
Next Post: «

Comments

  1. Christopher Lee Tingen said on December 30, 2021 at 9:01 pm
    Reply

    government and public accesest yo my account done by government will pay for there damage pne way ir another

  2. AAA said on May 12, 2018 at 12:56 pm
    Reply

    Our Lucy is getting very loosey — we must save this Lucy before it becomes a dust mosey e???

  3. Anonymous said on May 12, 2018 at 7:00 am
    Reply

    This has nothing to do with the technology behind it. Google just doesn’t properly vet extensions. The same indiligence with XUL extensions would have your entire web browser under control.

  4. Wayfarer said on May 12, 2018 at 1:06 am
    Reply

    FFS – it’s Google !!!!!!!

    Was any sensible person expecting otherwise ??!!

    We use this stuff because it’s there and there’s usually little other choice.

    But how long has it been since ANY user with two brain cells connected had the SLIGHTEST confidence in “Google-approved” products – either in Chrome or Android?

  5. Sebas said on May 11, 2018 at 6:01 pm
    Reply

    Only reputable addons like Web Api Manager, and UBO, and one I have some questions about: Malwarebytes Browser Extension BETA. But that is only used for a general Google Chrome profile, never for my shopping and login profiles.

    It seems to stop a lot of trackers/ malware, but being from Mbam, privacy could well be compromised. I will however read and implement your article about verifying. Thanks for a useful reminder.

  6. 11r20 said on May 11, 2018 at 5:54 pm
    Reply

    The brainwashed Google lucy’s have always
    come up with solutions after creating the problems in the first place.

    Problem,reaction,solution.

    That’s how these crazed, doped up on LSD Mountain View Ca. lucy’s roll…And since they receive U.S. goobermint fiat for their covert data collection/spy services and censorship duties…the google lucy’s are and always will be above the law.

  7. beemeup5 said on May 11, 2018 at 3:55 pm
    Reply

    WebExtensions will be more like Chrome extensions. They’ll be more secure!

    Yeaaah NO.

  8. ULBoom said on May 11, 2018 at 2:52 pm
    Reply

    I use three extensions in Chromium, they add simple features that should be there but aren’t. An easy to use zoom, cache cleaner and new tab homepage thing. It took hours to find these after rejecting many, many poorly functioning data collection sham extensions with 10^50 fake five star ratings. I do verify what extensions do but why trust anything in the chrome store when chrome is just a browser based ad server?

    Once or twice I’ve seen an opt out FF install bundled with other software but chrome opt outs are hidden everywhere; then there’s the whole android phone universe. With all the volunteers out there doing QA on large companies’ software, google, ms, etc., have no reason to rigorously vet these malicious extensions if their ad business isn’t hurt by them. They get away with cursory checks. Periodically, google announces a clamp down on malware so they appear diligent but malware continues.

  9. ua19 said on May 11, 2018 at 11:21 am
    Reply

    Password generator
    chrome://flags/#enable-password-generation
    chrome://flags/#enable-manual-password-generation

    Bookmarks sync
    Just sign in chrome and sync bookmarks, settings, passwords,… for all your devices

  10. AAA said on May 11, 2018 at 8:34 am
    Reply

    Poor Google baby…. been tackling with the malicious extensions for so long!!!
    How about build and five majority of the users what they actually seek in a browser:
    – Ad block / Tracking protection
    -Bookmarks sync
    -Password generator
    -Secure VPN
    -Cinema / nightmode.

    Rather than working on converting a mere browser into an OS. e???

  11. Nik said on May 11, 2018 at 7:34 am
    Reply

    I am not getting ads even though I have whitelisted you in Ublock Origin in Firefox. Works fine in Chrome.

    1. Richard Allen said on May 11, 2018 at 2:36 pm
      Reply

      If you have uBO disabled and are still not seeing ads I would think some other type of content blocking is still being used.

      FF Tracking Protection for instance will actually block virtually all ads. Not that I’ve spent a lot of time using Tracking Protection by itself but I am yet to see an ad when it is the only active content blocker. Any other type of tracking protection will also block most if not all ads, Ghostery is one example. Ads and tracking are so intertwined nowadays that it is hard to block one without inadvertently blocking the other. Oh well! :)

      If you still see ads when using Chrome and gHacks is whitelisted, that rules out system wide blocking like with a hosts file. So it has to be something in your FF configurationa€| addons, javascript not enabled, and so forth.

Leave a Reply

Check the box to consent to your data being stored in line with the guidelines set out in our privacy policy

We love comments and welcome thoughtful and civilized discussion. Rudeness and personal attacks will not be tolerated. Please stay on-topic.
Please note that your comment may not appear immediately after you post it.