A malicious Chrome extension masquerading as GoogleTranslate that can steal sensitive browser data, live-stream web sessions, and allow threat actors to remotely interact with Chrome windows while keeping their activity out of the victim’s view. The operation begins with a suspected Rust-based malware loader. VMRay researchers found that the binary drops a malicious Chrome extension alongside an AutoIt script, which subsequently deploys the Stealcv2 information-stealing malware. GoogleTranslate Chrome Extension The multi-stage infection chain gives attackers both traditional endpoint-stealing capabilities and unusually deep control over the victim’s browser environment. Once installed, the fraudulent extension can collect a...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!