Fake GoogleTranslate Chrome Extension Lets Attackers Remotely Control Your Browsers
Brief
A malicious Chrome extension masquerading as GoogleTranslate that can steal sensitive browser data, live-stream web sessions, and allow threat actors to remotely interact with Chrome windows while keeping their activity out of the victim’s view.
The operation begins with a suspected Rust-based malware loader. VMRay researchers found that the binary drops a malicious Chrome extension alongside an AutoIt script, which subsequently deploys the Stealcv2 information-stealing malware.
GoogleTranslate Chrome Extension
The multi-stage infection chain gives attackers both traditional endpoint-stealing capabilities and unusually deep control over the victim’s browser environment.
Once installed, the fraudulent extension can collect a broad range of browser-resident data. This includes browsing history, saved bookmarks, installed extension details, cookies, and stored credentials.
