Criminals infected more than 100,000 computers with browser extensions that stole login credentials, surreptitiously mined cryptocurrencies, and engaged in click fraud. The malicious extensions were hosted in Google’s official Chrome Web Store.
The scam was active since at least March with seven malicious extensions known so far, researchers with security firm Radware reported Thursday. Google’s security team removed five of the extensions on its own and removed two more after Radware reported them. In all, the malicious add-ons infected more than 100,000 users, at least one of which was inside a “well-protected network” of an unnamed global manufacturing firm, Radware said.
A Google spokeswoman said company employees removed the extensions from the Chrome Web Store and the infected users’ browsers within hours of receiving the report.
The botnet also installed cryptocurrency miners that mined the monero, bytecoin, and electroneum digital coins. Over the past six days, the attackers appeared to generate about $1,000 in digital coin, mostly in monero. To prevent users from removing the malicious extensions, the attackers automatically closed the extensions tab each time it was opened and blacklisted a variety of security tools provided by Facebook and Google.
The seven extensions masqueraded as legitimate extensions. Their names were:
- Divinity 2 Original Sin: Wiki Skill Popup
Thursday’s Radware blogpost includes extension IDs for each one.
The extensions came to the attention of Radware researchers through machine-learning algorithms that analyzed communication logs of the protected network that was infected. The Radware researchers said they believe the group behind the extensions has never been detected before. Given the regular success in getting malicious extensions hosted in the Chrome Web Store, it wouldn’t be surprising if the group strikes again.