216.73.217.22

Data-stealing Chrome extensions impersonate Fortinet, YouTube, VPNs

· Published 22/05/2025 11:17 · Modified 22/05/2025 11:30

Export JSON

Essential information

Published
22/05/2025 11:17
Modified
22/05/2025 11:30
Tags
2025-05-22 browser security chrome extensions cookie stealing data theft google web store malicious domains remote script execution vpn impersonation
Related entities
25 observables, 8 techniques (mitre)

Description

A campaign targeting the Google Chrome Web Store has deployed over 100 malicious browser extensions masquerading as legitimate tools like VPNs, AI assistants, and crypto utilities. These extensions, while offering some promised functionality, secretly connect to threat actor infrastructure to steal user information and execute remote scripts. They can modify network traffic, deliver ads, perform redirections, and act as proxies. The campaign, discovered by DomainTools researchers, involves numerous fake domains promoting these tools. The extensions request permissions that enable cookie theft, DOM-based phishing, and dynamic script injection. Risks include account hijacking, , and browsing activity monitoring. Some extensions remain on the Chrome Web Store despite Google's removal efforts.

External references