HT TECH wants to start sending you push notifications. Click allow to subscribe

Google removed over 500 malicious Chrome extensions that affected 1.7 million users

Google with security researchers removed over 500 malicious Chrome extensions which are expected to be part of a larger campaign.

By: HT CORRESPONDENT
Updated on: Feb 14 2020, 17:48 IST
Google was harbouring 500 malicious Chrome extensions. (Pixabay)

Google has been removed over 500 malicious Chrome extensions from its Web Store. These Chrome extensions are said to have been part of a large malware operation and were active for two years.

Google worked with independent security researcher Jamila Kaya and Cisco's Duo Security to investigate and uncover the malicious Chrome extensions. Duo Security's Chrome extension security tool CRXcavator to identify copycat Chrome extensions that infected users by injecting malicious ads. Over 1.7 million users were found to be affected by these malicious Chrome extensions.

You may be interested in

Mobiles Tablets Laptops
2% OFF
Google Pixel 7 5G
  • Obsidian
  • 8 GB RAM
  • 128 GB Storage
₹58,990₹59,999
Buy now
31% OFF
Google Pixel 7 Pro 5G
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹58,990₹84,999
Buy now
Google Pixel 7A
  • Charcoal
  • 8 GB RAM
  • 128 GB Storage
₹43,999
Check details
5% OFF
OnePlus 11R
  • Sonic Black
  • 8 GB RAM
  • 128 GB Storage
₹37,999₹39,999
Buy now
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,990₹74,999
Buy now
41% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹52,990₹89,999
Buy now
41% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹34,490₹57,999
Buy now
40% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,350₹51,990
Buy now
35% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹25,999₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,668₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹16,998
Check details

These extensions even managed to bypass the fraud detection of the Chrome Web Store. Further investigation revealed these infected Chrome extensions could have been part of a larger campaign to hack into users' browsers and extract data. How hackers managed to do this is through a popular technique called "malvertising". Hackers manage to utilise advertising cookies and redirects through which they control callbacks and bypass detection on the Chrome Web Store.

Also read: Looking for a smartphone? To check mobile finder click here.

"Malvertising often occurs within other programs, acting as a vehicle for multiple forms of fraudulent activity, including ad-fraud, data exfiltration, phishing, and monitoring and exploitation. Alternatively, it also emerges in multipart malicious campaigns that involve advertising collection and defraudment," Jamila Kaya and Jacob Rickerd explains in a blog post.

Another reason behind this is the nature of browser extensions which are known to have weak security and privacy.

"The Chrome extension creators had specifically made extensions that obfuscated the underlying advertising functionality from users. This was done in order to connect the browser clients to a command and control architecture, exfiltrate private browsing data without the users knowledge, expose the user to risk of exploit through advertising streams, and attempt to evade the Chrome Web Store's fraud detection mechanisms," the security researchers further explained.

Although the Chrome extensions have been removed hackers could still target browser extensions. The security researchers advises users to check the browser extensions they user, to remove those unused and also to report any unknown ones.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 14 Feb, 17:01 IST

Sale

Mobiles Tablets Laptops
5% OFF
Google Pixel 7A
  • Charcoal
  • 8 GB RAM
  • 128 GB Storage
₹41,990₹43,999
Buy now
48% OFF
Samsung Galaxy S23 FE
  • Mint
  • 8 GB RAM
  • 128 GB Storage
₹41,944₹79,999
Buy now
13% OFF
Samsung Galaxy A55
  • Awesome Iceblue
  • 8 GB RAM
  • 128 GB Storage
₹39,999₹45,999
Buy now
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
57% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹19,999₹47,000
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
27% OFF
Samsung Galaxy Tab S8
  • Silver
  • 8 GB RAM
  • 128 GB Storage
₹59,999₹81,999
Buy now
21% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹88,858₹113,098
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
22% OFF
Asus ROG Strix G15 G513RC HN085WS Laptop
  • Electro Punk
  • 16 GB RAM
  • 1 TB SSD
₹70,990₹90,990
Buy now
30% OFF
Asus ROG Strix G15 G513QY HQ032WS Laptop
  • Original Black
  • 16 GB RAM
  • 1 TB SSD
₹79,990₹113,990
Buy now
33% OFF
Asus VivoBook Go 15 OLED E1504GA NJ323WS Laptop
  • Green Grey
  • 8 GB RAM
  • 512 GB SSD
₹33,990₹50,990
Buy now