WELCOME TO EHOST.COM.NP

Thursday, January 18, 2018

Half Million Users Infected By Harmful Chrome Extensions

ads space

Click-fraud browser extensions pulled from Google’s Chrome Web Store.

In much the same way that smartphone apps help you personalize your device to your own specifications for productivity and enjoyment, browser extensions help you use the internet with your own key personalizations. These extensions are typically downloaded from the browser’s catalog of tools, and offer a wide variety of functions.

However, extensions are notorious for carrying some extra baggage, namely malicious code that often runs unnoticed by the user. Google Chrome is one such browser that has had problems in the past, and now, thanks to security researchers at ICEBRG, faces plenty more… 500,000 more, to be exact.

Half Million Users Infected By Harmful Chrome Extensions

Malicious browser extensions enabled criminals to impact over 500k users and global businesses.

Anomalies spotted

After finding a strange increase in output from one computer they were monitoring, Justin Warner and Mario De Tore investigated the cause and found four Chrome extensions that contained the code. The extensions included Change HTTP Request Header, Nyoogle – Custom Logo for Google, Lite Bookmarks, and Stickies – Chrome’s Post-it Notes.

It’s worth noting that, according to Warner and De Tore, “The Change HTTP Request Header extension itself does not contain any overtly malicious code. However, ICEBRG identified two items of concern that, when combined, enable the injection and execution of arbitrary JavaScript code via the extension.” That means the extension itself might not trigger any suspicious internal behaviors but when combined with other extensions, could pose a threat.

Hijacking users’ browsers

ICEBRG’s explanation of their findings is fairly technical, but at first glance, it seems that an external agent was hijacking users’ browsers in order to redirect to advertising sites to reap the benefits of a click fraud campaign. However, as Warner and De Tore explain, that is by far not the only capability with these compromised extensions.

“During the time of observation, the threat actor utilized this capability exclusively for visiting advertising related domains indicating a potential click fraud campaign was ongoing. Click fraud campaigns enable a malicious party to earn revenue by forcing victim systems to visit advertising sites that pay per click (PPC). The same capability could also be used by the threat actor to browse internal sites of victim networks, effectively bypassing perimeter controls that are meant to protect internal assets from external parties.”

ICEBRG alerted the pertinent security agencies and Google itself, and Google has removed those extensions from the browser store.

The good news? You can trust FileHippo for a huge range of safe browsers and extensions

ads space
ADS SPACE

0 comments:

Post a Comment

Categories

Article How-to All Posts WordPress Android Web design Blogger Plugins CSS Google JQuery Plugins Programming Reviews Web Hosting Blogger Blogging Blogging Tips Tricks Web Development Facebook Git Internet Make Money Online Social Plugins Tips Tips and Tricks Tools Tutorials Windows WordPress Plugins Blogging Tips and Tricks Freebies GSM Google Analytics HTML How To's JavaScript Plugin Development S.E.O SEO SMS SmartPhone Social Media Tips amp; Tricks Top-Most Updates Webmaster Tools Whatsapp Applications Apps Blogger Basics Documentary Downloads Entertainment Gadgets Games Gmail Google AdSense Guest Post IPhone Make Money Blogging SVN Security Softwares Web Hosting Tips and Tricks Wordpress Tips Wordpress Tips and Tricks hostgator iOS Advertising Networks Advertising Technology Affiliates Antivirus Audience amp; Traffic Biography Blog post Blog post Blogger Blogger Errors Blogger Tips Blogger Tools Blogger Widget Blogosphere Bogger Widgets CSS selectors CSS symbols CSS3 Computer amp; Internet Content Writing Coupon Codes Data amp; Analytics Deleted blog Design DoubleClick for Publishers Email and newsletter marketting Email marketing Excel Tips Excel Tips and Tricks Facebook Tricks Feed Feedburner Feedburner subscribers Font Fun GitHub Giveaways Gmail primary inbox Gmail tabs Google sign-in Guides HTML amp; CSS HTML5 Infographics Inspirational Instagram Internet Marketing Internet Tips amp; Tricks Job Listings Knowledge Life Hacks Lists Make-Money Monetization amp; Conversion Monetize Navigation Online Marketing Other PHP Tutorials Passport Publishing amp; Content Quotes RSS Sidebar Smartphones Social Networking Status Tech Tech Blog Technology Telegram Themes UI / UX User Psychology amp; Research VB.Net Web Tools Web browser Widget Windows Tips Windows-10 ad viewability admin notice blogging tools bluehost cherry-pick clone cors custom scrollbar customizer dismissible notices duplicate post feed title git branch git clone gpg gpg2 hybridauth iPad icon font notice responsive wordpress theme same origin policy scrollbar signed git commit smartsvn theme customizer vcs wordpress theme wordpress themes

Blog Archive