In a recent cyber threat revelation, researchers have identified a total of 19 browser extensions—18 for Google Chrome and one for Microsoft Edge—that are equipped with harmful code designed to steal cryptocurrency wallet secrets. These extensions, uncovered by Karlo Zanki from Socket Security, have been gradually released over the past six months, hinting at a potentially long-running operation.
Identifying the Threat
The extensions in question share similar code characteristics and methods, suggesting a coordinated campaign possibly active since February 2024. Socket Security has cataloged this activity under the moniker “Superior.” The strategy employed by these cybercriminals involves either taking over legitimate extensions or releasing initially clean versions that later evolve to maliciously compromise users’ data.
Among the 19 extensions, 14 were directly created by the cyber actors, while five were acquired from previous developers. Notably, some of these extensions had previously been flagged for malicious activities, such as “QuickLens – Search Screen with Google Lens,” which had been identified earlier this year for malware distribution and data harvesting.
Technical Insights and Impact
A detailed analysis reveals that these extensions often perform dual functions—they appear to serve their intended purpose while also connecting to malicious servers. This duality allows the extensions to transmit user data, execute arbitrary commands, and maintain persistent connections with command-and-control (C2) servers.
The extension “Enable Right Click & Copy — Smart Unlock + OCR” poses a significant risk, with an installation base spanning 80,000 users across Chrome and Edge. Each extension can communicate with C2 servers and dynamically adapt its behavior based on received instructions, facilitating targeted data exfiltration and reducing detection likelihood.
Broader Implications and Future Outlook
The malicious extensions employ sophisticated techniques, such as stripping Content Security Policy headers and injecting JavaScript modules across web pages. A total of 16 modules were identified, encompassing a range of malicious activities from wallet draining to credential theft.
The identity of the perpetrators remains a mystery, though their sustained success over two years highlights their proficiency. The most significant risk stems from their strategy of acquiring legitimate extensions and infusing them with harmful capabilities, exploiting the auto-update feature of browsers to maximize reach and impact.
In conclusion, the exposure of these malicious extensions underscores the importance of vigilance in cybersecurity, especially for users dealing with cryptocurrency. As the threat landscape evolves, staying informed and cautious about the extensions installed on browsers is crucial to protecting sensitive information.
