Monday, March 3, 2025
HomeComputer SecurityBeware !! Chrome Spyware Extensions Stealing Facebook Data, Location and Millions of...

Beware !! Chrome Spyware Extensions Stealing Facebook Data, Location and Millions of Users Browser History

Published on

SIEM as a Service

Follow Us on Google News

Malicious Chrome extensions that contain huge spyware campaign stealing Facebook data, users location and browsing histories of millions of users.

The researcher conducting the deep scan of all publicly available Chrome extensions which revealed a lot of suspicious activities and the malicious requests that is made to various Facebook domains.

These Chrome extensions are downloaded and used by more than 420,000 users. Following extension are discovered as a spyware extension.

It’s not limited only by Chrome extensions but the researcher identified a malicious Android app that performs the very similar operation of chrome extensions that installed more than 11,000,000 users according to Google Play and selling the installed users data.

Malicious apps are connecting to the Unimania servers and it was unclear that who is behind the Unimania’s owners or affiliates and profit of the stolen data.

Stealing the data from Browser

Once the malicious extension gets installed, it will collect the victims facebook data whenever users logged into Facebook after start the browser.

Later it parses the victim’s browser history including the sensitive information such as your purchase history and sends it to anum-public-panel-prod.s3.amazonaws.com amazon s3 bucket which rented by the Malware authors.

According to adguard, Users data that being shared including  Facebook “interests” and shockingly they can also see all of the victims Facebook posts, sponsored posts, tweets, the YouTube videos and ads you see or interact with, along with a poorly hashed user ID and totally UN-hashed location data.

Malware authors linked this malicious extentsions privacy policy to the Unimania. Inc, that indicates the Information we collect includes nonpersonally identifiable demographic and psychographic data as well as sponsored campaigns, advertisements or posts that target you directly or that have been shared with you.

This is not malicious activities are not only associated with Chrome extension but one particular app that was connecting to the Unimania servers.

This was an alternative Facebook client called Fast – Social App with a record of more than 10,000,000 installs according to Google Play.

The campaign is run by a supposed Israeli company named “Unimania, Inc.” Unfortunately, I was not able to trace this further back to Unimania’s owners or affiliates and I can’t say who is profiting from the data. adguard Researcher said.

Also Read:

Chrome 67 Released With Fix for 34 Security Issues and Support for Password-Free Logins

PassProtect – Google Chrome Plugin Tell You If your Password has Been Breached

Malicious Chrome and Edge Browser Extension Deliver Powerful Backdoor & RAT to Spy Victims PC

100,000 Users Infected With the Password Stealing Malicious Chrome Extension Distributed Through Facebook

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Google Launches Shielded Email to Keep Your Address Hidden from Apps

Google is rolling out a new privacy-focused feature called Shielded Email, designed to prevent apps...

Hackers Using PowerShell and Microsoft Legitimate Apps to Deploy Malware

Cybersecurity experts are warning of an increasing trend in fileless attacks, where hackers leverage...

JavaGhost: Exploiting Amazon IAM Permissions for Phishing Attacks

Unit 42 researchers have observed a threat actor group known as JavaGhost exploiting misconfigurations...

New Poco RAT Via Weaponized PDF Attacking Users to Capture Sensitive Data

A new variant of malware, dubbed "Poco RAT," has emerged as a potent espionage...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Winos4.0 Malware Targets Windows Users Through Malicious PDF Files

A new wave of cyberattacks leveraging the Winos4.0 malware framework has targeted organizations in...

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government,...