100,000 Users Infected With the Password Stealing Malicious Chrome Extension Distributed Through Facebook

A new malware campaign propagating via crafted socially-engineered links on Facebook abuses the users by installing a malicious chrome extension and performs crypto mining, click fraud, Password theft and more.

Facebook Malware campaigns are not new, this new campaign Modus operandi is same as like any other previous malware campaigns.

Radware’s Threat Research team revealed that this group is active since at least March of 2018 and it infects more than 100,000 users in about more than 100 countries. The sophisticated group remains undetected until now as they keep on changing their mechanism for malware distribution.

The malware dubbed Nigelthorn spreads at a rapid pace, it redirects users to the fake youtube page and forces to install the Chrome extension to play the video.

Once the user click’s on Add Extension then the malicious extension will be installed and now the machine is a part of the bot and it is compatible with both Windows and Linux.

According to Radware ” Over 75% of the infections cover the Philippines, Venezuela, and Ecuador. The remaining 25% are distributed over 97 other countries”.

Malware kill chain

The campaign abuses the legitimate Nigelify application and inserts the malicious script to start the malware campaign.

Radware team observed seven of such malicious extensions and four of them already blocked by Google’s security algorithms.

Once the malware installed it establishes the connection with C&C server to download the required malicious JavaScript.

The malware mainly focused on extracting Facebook login credentials and Instagram cookies. Another plugin that downloaded by malware generates cryptocurrencies, Radware observed the group tried mining different coins based on the CryptoNight algorithm (Monero, Bytecoin, and Electroneum).

As like any other malware, it tries it’s best to remain persistent by preventing the victims removing the malicious extension. If it detects victims opening the chrome extension management “chrome://extensions/” then it closes the page immediately.

Guru baran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Russian Hackers Actively Attacking Small-scale Infrastructure Sectors

Russian hacktivists increasingly target small-scale operational technology (OT) systems across North America and Europe. These attacks, primarily focused on the…

1 hour ago

Threat Actors Attacking MS-SQL Servers to Deploy Ransomware

Cybersecurity experts have uncovered a series of sophisticated cyberattacks targeting poorly managed Microsoft SQL (MS-SQL) servers. The attackers, identified as…

3 hours ago

REvil Ransomware Affiliate Sentenced for 13 Years in Prison

A Ukrainian national, Yaroslav Vasinskyi, has been sentenced to 13 years and seven months in prison. Vasinskyi, known in the…

6 hours ago

USB Malware Attacks Targeting Industrial Systems Adapts LOL Tactics

Honeywell's 2024 GARD USB Threat Report analyzes malware discovered on USB devices used in industrial settings, highlighting a significant increase…

6 hours ago

Attention all Windows Users! The Microsoft April Security Update Could Break Your VPN

In a recent development that has caught the attention of IT administrators and users alike, Microsoft has acknowledged a significant…

7 hours ago

Panda Restaurant Corporate Systems Hacked: Customer Data Exposed

Panda Restaurant Group, Inc., a leading name in the fast-food industry, has confirmed a significant breach in its corporate data…

9 hours ago