Thursday, October 10, 2024
HomeComputer Security100,000 Users Infected With the Password Stealing Malicious Chrome Extension Distributed Through...

100,000 Users Infected With the Password Stealing Malicious Chrome Extension Distributed Through Facebook

Published on

A new malware campaign propagating via crafted socially-engineered links on Facebook abuses the users by installing a malicious chrome extension and performs crypto mining, click fraud, Password theft and more.

Facebook Malware campaigns are not new, this new campaign Modus operandi is same as like any other previous malware campaigns.

Radware’s Threat Research team revealed that this group is active since at least March of 2018 and it infects more than 100,000 users in about more than 100 countries. The sophisticated group remains undetected until now as they keep on changing their mechanism for malware distribution.

- Advertisement - EHA

The malware dubbed Nigelthorn spreads at a rapid pace, it redirects users to the fake youtube page and forces to install the Chrome extension to play the video.

malware campaign

Once the user click’s on Add Extension then the malicious extension will be installed and now the machine is a part of the bot and it is compatible with both Windows and Linux.

According to Radware ” Over 75% of the infections cover the Philippines, Venezuela, and Ecuador. The remaining 25% are distributed over 97 other countries”.

malware campaign
Malware kill chain

The campaign abuses the legitimate Nigelify application and inserts the malicious script to start the malware campaign.

Radware team observed seven of such malicious extensions and four of them already blocked by Google’s security algorithms.

malware campaign

Once the malware installed it establishes the connection with C&C server to download the required malicious JavaScript.

The malware mainly focused on extracting Facebook login credentials and Instagram cookies. Another plugin that downloaded by malware generates cryptocurrencies, Radware observed the group tried mining different coins based on the CryptoNight algorithm (Monero, Bytecoin, and Electroneum).

As like any other malware, it tries it’s best to remain persistent by preventing the victims removing the malicious extension. If it detects victims opening the chrome extension management “chrome://extensions/” then it closes the page immediately.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Mozilla Warns Of Firefox Zero-Day Actively Exploited In Cyber Attacks

A critical use-after-free vulnerability affecting Firefox and Firefox Extended Support Release (ESR) is being...

SpyCloud Embeds Identity Analytics in Cybercrime Investigations Solution to Accelerate Insider and Supply Chain Risk Analysis & Threat Actor Attribution

IDLink, SpyCloud’s new automated digital identity correlation capability, is now core to its industry-leading...

Abusix and Red Sift Form New Partnership, Leveraging Automation to Mitigate Cyber Attacks

The agreement has marked over 600,000 fraudulent domains for takedown in just two months...

Hackers Exploiting Zero-day Flaw in Qualcomm Chips to Attack Android Users

Hackers exploit a zero-day vulnerability found in Qualcomm chipsets, potentially affecting millions worldwide.The flaw,...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

LemonDuck Malware Exploiting SMB Vulnerabilities To Attack Windwos Servers

The attackers exploited the EternalBlue vulnerability to gain initial access to the observatory farm,...

DCRAt Attacking Users Via HTML Smuggling To Steal Login Credentials

In a new campaign that is aimed at users who speak Russian, the modular...

LummaC2 Stealer Leverages Customized Control Flow Indirection For Execution

The LummaC2 obfuscator employs a novel control flow protection scheme designed specifically for its...