A Google Chrome Web Store campaign uses over 100 malicious browser extensions that mimic legitimate tools, such as VPNs, AI assistants, and crypto utilities, to steal browser cookies and execute remote scripts secretly. The extensions offer some of the promised functionality, but also connect to the threat actor's infrastructure to steal user information or receive commands to execute. Additionally, the malicious Chrome extensions can modify network traffic to deliver ads, perform redirections, or proxying. The campaign was discovered by security researchers at DomainTools, who spotted over 100 fake domains promoting the tools to unsuspecting users, likely through malvertising. DomainTools' list of over 100 malicious websites includes multiple fake VPN brands as well as attempts to impersonate legitimate brands, such as Fortinet, YouTube, DeepSeek AI, and Calendly: These websites include "Add to Chrome" buttons that link to malicious browser extensions on the Chrome Web Store, thus increasing the sense of legitimacy. Although Google removed many of the extensions DomainTools identified, BleepingComputer has confirmed that some remain on the Chrome Web Store. "The Chrome Web Store has removed multiple of the actor's malicious extensions after malware identification," explain the researchers. "However, the actor's persistence and the time lag in detection and removal pose a threat to users seeking productivity tools and browser enhancements." While each extension performs diff...
Data-stealing Chrome extensions impersonate Fortinet, YouTube, VPNs
BleepingComputer
·Bill Toulas
·Published May 21, 2025
·Updated
Affected Software
4 affected components
Google Chrome
Fortinet VPN
DeepSeek AI
Google Chrome
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a campaign involving malicious Chrome extensions that impersonate legitimate tools to steal user data.
2
What security implications are discussed in this article?
The security implications include the unauthorized theft of browser cookies and the execution of remote scripts through malicious extensions.
3
What products or software are affected by the malicious extensions?
The affected software includes Google Chrome, Fortinet VPN, and tools impersonated by the extensions such as AI assistants and crypto utilities.
4
How many malicious extensions are involved in this Chrome campaign?
The campaign involves over 100 malicious browser extensions aimed at deceiving users.
5
What methods do these malicious Chrome extensions use to exploit users?
These extensions steal browser cookies and execute scripts secretly without user consent.