Google Attack Warning—Chrome Hackers Target Gmail And YouTube Users
108 dangerous Google Chrome extensions targeted Gmail, YouTube, TikTok and Telegram users.
Getty ImagesA total of 108 dangerous Google Chrome web browser extensions have been identified as part of a coordinated threat campaign targeting Gmail and YouTube users, as well as Telegram and TikTok. All the malicious extensions connected back to a single command-and-control infrastructure operated by the threat actors had around 20,000 known installs at the time the security report was published on April 13.
Most concerning of all, perhaps, is that the report author, Kush Pandya from the Socket security Threat Research Team, said that: "The extensions remain live at the time of writing. We have submitted takedown requests to the Chrome Web Store security team and Google Safe Browsing." I have reached out to Google for a statement, but in the meantime, here's what we know about the threat campaign.
MORE FROM FORBESBooking.com Confirms Data Breach, Reservation PIN Codes Changed
The Google Chrome Browser Extensions Attack By The Numbers
When it comes to web browser extensions, at least the dodgy kind exploited by threat actors, there is a danger that the constant flow of news headlines will leave users fatigued and complacent. That would be a huge mistake, given that the compromise of the Chrome Trust Wallet extension saw $7 million stolen from users. Not all numbers are that high, of course, but the Socket report reminds us that coordinated threat campaigns centered on malicious extensions cannot be ignored.
The researchers found that:
-
54 extensions were designed to steal Google account identity via OAuth2
-
45 extensions contained a malware backdoor to launch arbitrary URLs on browser start
-
2 extensions that not only stripped YouTube security headers but then went on to inject ads
-
2 extensions that injected content scripts into every page that the browser user visited
-
1 extension that exfiltrated Telegram Web sessions every 15 seconds
-
1 extension that included a staged infrastructure for Telegram session theft, although that had not been activated at the time of the report
-
1 extension that stripped TikTok security headers and injected ads
-
1 extension that proxied all translation requests through the threat actor's server
Look, I'm not going to candy-coat it: web browser extensions are a hot security threat mess. And let's not be too precious here, while Google Chrome is the biggest target with its 3.5 million users, it's not the only one. So, yes, recently I reported how a previously legitimate Chrome extension was bought by a malicious actor and weaponized . But I've also warned about dangerous Mozilla Firefox extensions , brought to my attention, coincidentally, by the same Socket Threat Research team.
MORE FROM FORBESHackers Give Rockstar Games Until April 14 To Pay For Stolen Data
Google has stated that it:
-
Reviews extensions before they're published on the Chrome Web Store
-
Continuously monitors extensions after they're published
What's more. Google said, "The top of the extensions page (chrome://extensions) warns you of any extensions you have installed that might pose a security risk. (If you don't see a warning panel, you probably don't have any extensions you need to worry about.)"
It would seem, given the Socket report, that something, somewhere, is not working as it should. "We have submitted takedown requests to the Chrome Web Store security team and Google Safe Browsing," Kush Pandya said. I recommend running a Google Security Check to ensure you have all protections activated, and will update this article once Google has responded to my statement request.
This article was originally published on Forbes.com

