{"id":85878,"date":"2020-06-20T01:42:41","date_gmt":"2020-06-19T23:42:41","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/111-chrome-dopolnenij-zagruzhennyh-32-mln-raz-ulicheny-v-zagruzke-konfidenczialnyh-dannyh"},"modified":"2020-06-20T01:42:41","modified_gmt":"2020-06-19T23:42:41","slug":"111-chrome-dopolnenij-zagruzhennyh-32-mln-raz-ulicheny-v-zagruzke-konfidenczialnyh-dannyh","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/111-chrome-dopolnenij-zagruzhennyh-32-mln-raz-ulicheny-v-zagruzke-konfidenczialnyh-dannyh","title":{"rendered":"111 Chrome extensions, downloaded 32 million times, caught collecting sensitive data","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Awake Security <noindex><a rel=\"nofollow\" href=\"https:\/\/awakesecurity.com\/blog\/the-internets-new-arms-dealers-malicious-domain-registrars\/\">has announced<\/a><\/noindex> on the detection of <noindex><a rel=\"nofollow\" href=\"https:\/\/awakesecurity.com\/wp-content\/uploads\/2020\/06\/GalComm-Malicious-Chrome-Extensions-Appendix-B.txt\">111 extensions<\/a><\/noindex> for Google Chrome that send confidential user data to external servers. These extensions had access to taking screenshots, reading clipboard content, analyzing the presence of access tokens in cookies, and intercepting input in web forms. In total, the identified malicious extensions accounted for 32.9 million downloads in the Chrome Web Store, with the most popular one (Search Manager) being downloaded 10 million times and receiving 22,000 reviews.<\/p>\n<p>It is believed that all the extensions in question were developed by the same group of attackers, as all  <noindex><a rel=\"nofollow\" href=\"https:\/\/cdn2.hubspot.net\/hubfs\/3455675\/wp-the-internets-new-arms-dealers-malicious-domain-registrars.pdf\">used<\/a><\/noindex> a standard distribution scheme and organization of confidential data capture, as well as shared design elements and repetitive code. <noindex><a rel=\"nofollow\" href=\"https:\/\/awakesecurity.com\/wp-content\/uploads\/2020\/06\/GalComm-Malicious-Chrome-Extensions-in-store-extensions.txt\">79 extensions<\/a><\/noindex> containing malicious code were posted in the Chrome Store and have already been removed after a notification of malicious activity was sent. Many of the malicious extensions mimicked the functionality of various popular extensions, including those aimed at providing additional browser security, enhancing privacy while searching, converting PDFs, and format conversion.<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/cdn2.hubspot.net\/hubfs\/3455675\/wp-the-internets-new-arms-dealers-malicious-domain-registrars.pdf\"><img decoding=\"async\" alt=\"111 Chrome extensions, downloaded 32 million times, caught collecting sensitive data\" src=\"\/wp-content\/uploads\/2020\/06\/97315b840c3b4c73df5d18e042597872.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>Initially, extension developers would upload a clean version without malicious code to the Chrome Store, undergo reviews, and then in subsequent updates, introduce changes that would load malicious code after installation. To cover up traces of malicious activity, they also employed selective response techniques \u2014 the first request would yield a malicious download, while subsequent requests would return non-suspicious data. <\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/awakesecurity.com\/wp-content\/uploads\/2020\/06\/fig9.png\"><img decoding=\"async\" alt=\"111 Chrome extensions, downloaded 32 million times, caught collecting sensitive data\" src=\"\/wp-content\/uploads\/2020\/06\/aaabaffe86542c9a35b395536c0e9e34.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>The main avenues for distributing malicious extensions include the promotion of professionally-looking websites (like the one shown below) and placement in the Chrome Web Store, bypassing verification mechanisms to later load code from external sites. To circumvent restrictions on installing extensions only from the Chrome Web Store, attackers distributed modified Chromium builds with pre-installed extensions, as well as installations through already present adware applications in the system. Researchers analyzed 100 networks of financial, media, medical, pharmaceutical, oil and gas, and retail companies, as well as educational and government institutions, finding traces of the discussed malicious extensions in almost all of them. <\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/awakesecurity.com\/wp-content\/uploads\/2020\/06\/fig2.png\"><img decoding=\"async\" alt=\"111 Chrome extensions, downloaded 32 million times, caught collecting sensitive data\" src=\"\/wp-content\/uploads\/2020\/06\/aec68fca869e1fd7835749cf9c28aea7.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>During the campaign to spread malicious extensions, more than <noindex><a rel=\"nofollow\" href=\"https:\/\/www.awakesecurity.com\/wp-content\/uploads\/2020\/06\/GalComm-Registered-Domains-List-Appendix-A.txt\">15,000 domains<\/a><\/noindex>, overlapping with popular websites (such as gmaille.com, youtubeunblocked.net, etc.) or registered after the expiration of previously existing domains. These domains were also used in the infrastructure to manage malicious activity and to load malicious JavaScript inserts executed in the context of pages opened by users.<\/p>\n<p>Researchers suspected collusion with the domain registrar Galcomm, which registered 15,000 domains for malicious activities (60% of all domains issued by this registrar), but representatives of Galcomm <noindex><a rel=\"nofollow\" href=\"https:\/\/www.theregister.com\/2020\/06\/18\/chrome_browser_extensions_new_rootkit\/\">denied<\/a><\/noindex> these allegations and indicated that 25% of the listed domains have already been deleted or were not issued by Galcomm, while almost all the rest are inactive parked domains. Galcomm representatives also reported that prior to the public disclosure of the report, no one had contacted them, and they received the list of domains used for malicious purposes from a third party and are now conducting their own investigation.<\/p>\n<p>Researchers who identified the issue compare the malicious extensions to a new rootkit \u2014 many users conduct their main activities through their browsers, which grant access to shared document storage, corporate information systems, and financial services. In such cases, cybercriminals have no incentive to seek a complete compromise of the operating system to install a full rootkit; it is much easier to achieve the installation of a malicious browser extension and control the flow of confidential data through it. In addition to controlling transit data, the extension can request permissions to access local data, the webcam, and location. As practice shows, most users do not pay attention to the permissions requested, and 80% of 1000 popular extensions request access to data from all processed pages. <\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53190\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Awake Security \u0441\u043e\u043e\u0431\u0449\u0438\u043b\u0430 \u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0438 111 \u0434\u043e\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0439 \u043a Google Chrome, \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u044e\u0449\u0438\u0445 \u043d\u0430 \u0432\u043d\u0435\u0448\u043d\u0438\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u043a\u043e\u043d\u0444\u0438\u0434\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f. \u0412 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u0434\u043e\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0438\u043c\u0435\u043b\u0438 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044e \u0441\u043a\u0440\u0438\u043d\u0448\u043e\u0442\u043e\u0432, \u0447\u0442\u0435\u043d\u0438\u044e \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0433\u043e \u0431\u0443\u0444\u0435\u0440\u0430 \u043e\u0431\u043c\u0435\u043d\u0430, \u0430\u043d\u0430\u043b\u0438\u0437\u0443 \u043d\u0430\u043b\u0438\u0447\u0438\u044f \u0442\u043e\u043a\u0435\u043d\u043e\u0432 \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u0432 Cookie \u0438 \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0443 \u0432\u0432\u043e\u0434\u0430 \u0432 web-\u0444\u043e\u0440\u043c\u0430\u0445. \u0412 \u0441\u0443\u043c\u043c\u0435 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0435 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0434\u043e\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u043b\u0438 32.9 \u043c\u043b\u043d \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a \u0432 Chrome Web Store, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":85879,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-85878","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Awake Security \u0441\u043e\u043e\u0431\u0449\u0438\u043b\u0430 \u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0438\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/111-chrome-dopolnenij-zagruzhennyh-32-mln-raz-ulicheny-v-zagruzke-konfidenczialnyh-dannyh\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47111 Chrome-\u0434\u043e\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0439, \u0437\u0430\u0433\u0440\u0443\u0436\u0435\u043d\u043d\u044b\u0445 32 \u043c\u043b\u043d \u0440\u0430\u0437, \u0443\u043b\u0438\u0447\u0435\u043d\u044b \u0432 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0435 \u043a\u043e\u043d\u0444\u0438\u0434\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Awake Security \u0441\u043e\u043e\u0431\u0449\u0438\u043b\u0430 \u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0438\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/111-chrome-dopolnenij-zagruzhennyh-32-mln-raz-ulicheny-v-zagruzke-konfidenczialnyh-dannyh\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-06-19T23:42:41+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-06-19T23:42:41+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47111 Chrome extensions, downloaded 32 million times, caught stealing confidential data | ProHoster","description":"Awake Security reported the discovery of","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/111-chrome-dopolnenij-zagruzhennyh-32-mln-raz-ulicheny-v-zagruzke-konfidenczialnyh-dannyh","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47111 Chrome-\u0434\u043e\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0439, \u0437\u0430\u0433\u0440\u0443\u0436\u0435\u043d\u043d\u044b\u0445 32 \u043c\u043b\u043d \u0440\u0430\u0437, \u0443\u043b\u0438\u0447\u0435\u043d\u044b \u0432 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0435 \u043a\u043e\u043d\u0444\u0438\u0434\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Awake Security \u0441\u043e\u043e\u0431\u0449\u0438\u043b\u0430 \u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0438","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/111-chrome-dopolnenij-zagruzhennyh-32-mln-raz-ulicheny-v-zagruzke-konfidenczialnyh-dannyh","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-06-19T23:42:41+00:00","article:modified_time":"2020-06-19T23:42:41+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"85878","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 14:28:23","updated":"2022-09-27 16:37:49","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/85878","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=85878"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/85878\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/85879"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=85878"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=85878"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=85878"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}