THREAT OPS › Threat News › Attack of The Extensions
Attack of The Extensions
<p class="wp-block-paragraph" id="h-tl-dr-browser-extensions-can-turn-chromium-into-a-persistent-foothold-this-post-introduces-a-way-to-silently-install-extensions-turning-chromium-browsers-into-a-command-and-control-c2-platform-for-persistent-cookie-theft"><strong><em>TL;DR: </em></strong><em>Browser extensions can turn Chromium into a persistent foothold. This post introduces a way to silently i
Attributed threat actors
- Earth LuscaG1006
MITRE ATT&CK techniques
Indicators of compromise
- https://developer.chrome.com/docs/iwa/introductionurl
- https://developer.chrome.com/docs/extensions/develop/concepts/native-messagingurl
- https://developer.chrome.com/docs/extensions/reference/apiurl
- https://syntax-err0r.github.io/Silently_Install_Chrome_Extension.htmlurl
- https://chromium.googlesource.com/chromium/src/%2B/HEAD/services/preferences/tracked/pref_hash_store_impl.ccurl
- https://help.screencloud.com/en/articles/10114868-chromeos-playerurl
- https://www.xtralogic.com/remote-desktop-client-for-chrome-download/url
- https://support.1password.com/connect-1password-browser-app/url
- https://developer.chrome.com/docs/extensions/reference/manifest/keyurl
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90011url
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90013url
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90001url
- https://chromeenterprise.google/policies/extension-developer-mode-settings/url