Awake Security on the detection of for Google Chrome that send confidential user data to external servers. These extensions had access to taking screenshots, reading clipboard content, analyzing the presence of access tokens in cookies, and intercepting input in web forms. In total, the identified malicious extensions accounted for 32.9 million downloads in the Chrome Web Store, with the most popular one (Search Manager) being downloaded 10 million times and receiving 22,000 reviews.
It is believed that all the extensions in question were developed by the same group of attackers, as all a standard distribution scheme and organization of confidential data capture, as well as shared design elements and repetitive code. containing malicious code were posted in the Chrome Store and have already been removed after a notification of malicious activity was sent. Many of the malicious extensions mimicked the functionality of various popular extensions, including those aimed at providing additional browser security, enhancing privacy while searching, converting PDFs, and format conversion.
Initially, the developers posted a clean version without malicious code in the Chrome Store, passed the review, and then added changes in one of the updates that loaded the malicious code after installation. A technique called selective responses was also used to hide traces of malicious activity — the first request issued a malicious download, while subsequent requests provided unremarkable data.
The main avenues for distributing malicious extensions include the promotion of professionally-looking websites (like the one shown below) and placement in the Chrome Web Store, bypassing verification mechanisms to later load code from external sites. To circumvent restrictions on installing extensions only from the Chrome Web Store, attackers distributed modified Chromium builds with pre-installed extensions, as well as installations through already present adware applications in the system. Researchers analyzed 100 networks of financial, media, medical, pharmaceutical, oil and gas, and retail companies, as well as educational and government institutions, finding traces of the discussed malicious extensions in almost all of them.
During the campaign to spread malicious extensions, more than , overlapping with popular websites (such as gmaille.com, youtubeunblocked.net, etc.) or registered after the expiration of previously existing domains. These domains were also used in the infrastructure to manage malicious activity and to load malicious JavaScript inserts executed in the context of pages opened by users.
Researchers suspected collusion with the domain registrar Galcomm, which registered 15,000 domains for malicious activities (60% of all domains issued by this registrar), but representatives of Galcomm these allegations and indicated that 25% of the listed domains have already been deleted or were not issued by Galcomm, while almost all the rest are inactive parked domains. Galcomm representatives also reported that prior to the public disclosure of the report, no one had contacted them, and they received the list of domains used for malicious purposes from a third party and are now conducting their own investigation.
Researchers who identified the issue compare malicious extensions to a new rootkit — the primary activities of many users are conducted through the browser, which provides access to shared document storage, corporate information systems, and financial services. In such conditions, it makes no sense for attackers to seek a complete compromise of the operating system to install a full rootkit — it is much simpler to achieve the installation of a malicious browser extension and control the flow of confidential data through it. In addition to controlling transit data, the extension may request permissions to access local data, the web camera, and location. As practice shows, most users do not pay attention to the requested permissions, and 80% of the 1000 popular extensions request access to data on all processed pages.
Source: opennet.ru
