Internet security threats are everywhere, and even in stores that are already under the control of large technology companies like Google, it is still difficult to completely prevent malicious operations from malicious actors. Security researcher Jamila Kaya accidentally discovered a problematic malicious Chrome extension plug-in during a routine search for online security threats. After two months of digging around, she discovered a series of problems. This series of malicious operations had been active for at least two years, causing Google to delete more than 500 problematic extension plug-ins.

Researchers discover malicious Chrome extension plug-in, first app installed by more than 1.7 million people
After Jamila Kaya first discovered it, she contacted Cisco’s Duo security team. Later, it was discovered that these extension plug-ins were infected through browsers and became part of a larger data breach. The report pointed out that these plug-ins usually provide advertising services and are all part of copycat plug-ins, sharing almost the same functionality. Through cooperation, they tested dozens of plug-ins and used the security assessment tool CRXcavator.io to identify 70 matching patterns among 1.7 million users and provided the concerns to Google.

The Duo team goes on to explain that bad actors are increasingly using legitimate online activity to mask their malicious behavior, and one of the most popular channels is the use of advertising cookies and retargeting within them. This incredible technique, known as “malvertising,” occurs frequently in other applications and serves as a vehicle for many forms of fraudulent activity, including ad fraud, data breaches, phishing, and surveillance exploits. It has also appeared in multiple malicious campaigns involving ad harvesting and fraud.

The source code in these malicious extensions sometimes redirects users to membership login links on shopping sites such as Best Buy or Macy’s, and sometimes the target may be a download point for the malware. When researchers brought the issue to Google, Google responded. A spokesperson said that Google always takes action when the research community raises alerts about issues that violate company policies. In addition, Google said that they will continue to perform routine scans to find more extensions in question.
◎Data source:Cisco Duo
Source: KOCPC Chinese