Analysis reveals many malicious Chrome extensions
Posted on 20 August 2014.
An analysis of 48,332 browser extensions from the Chrome web store has revealed 130 outright malicious and 4,712 suspicious extensions, some of which have been downloaded by millions of users.


"The amount of critical and private data that web browsers mediate continues to increase, and naturally this data has become a target for criminals. In addition, the web’s advertising ecosystem offers opportunities to profit by manipulating a user’s everyday browsing behavior," the researchers noted in the paper detailing their findings.

"As a result, malicious browser extensions have become a new threat, as criminals realize the potential to monetize a victim’s web browsing session and readily access web-related content and private data."

To analyze the extensions, the researchers used Hulk, a dynamic analysis system of their own making, which flushes out the extensions' malicious behaviour.

"First, Hulk leverages HoneyPages, which are dynamic pages that adapt to an extension’s expectations in web page structure and content," they explained. Second, Hulk employs a fuzzer to drive the numerous event handlers that modern extensions heavily rely upon."

Among the malicious extensions they found, some perpetrated affiliate fraud and credential theft, others performed ad injection or replacement, and others still abused social networks for spamming.

The researchers also offered a set of recommendations that would prevent some of these attacks, and they hope Google will implement them.










Spotlight

Over 225,000 Apple accounts compromised via iOS malware

Researchers from Palo Alto Networks and WeipTech have unearthed a scheme that resulted in the largest known Apple account theft caused by malware. All in all, some 225,000 valid Apple accounts have been compromised.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  
DON'T
MISS

Tue, Sep 1st
    COPYRIGHT 1998-2015 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //