Google Warns Chrome Browser Users NOT To Activate Any Of These 500 Extensions
Google has warned Chrome users to not activate over 500 extensions due to fraudulent transactions targeted at users. On January 20, it was reported how Google had confirmed a publication or update of all paid-for extensions in the Chrome Web Store had been temporarily suspended.
The reason was cited as being a significant increase in the number of fraudulent transactions attempting to defraud users. Things have just got a lot worse, or a lot better, depending on whether you’re a glass-half-empty or half-full person: a total of 500 Chrome web browser extensions have been identified, and deactivated, that were stealthily uploading user data.
Researchers say the malicious campaign executed by these 500 Chrome extensions was operational since at least January 2019 but could date back as far as 2017.
Digging into Chrome web browser extension fraud
The fraud campaign was unearthed in a joint operation between Cisco’s Duo Security team and an independent security researcher, Jamila Kaya. They initially discovered that 70 Chrome web browser extensions, which had been installed by at least 1.7 million users, were obfuscating malicious advertising functionality from those unknowing users. Using a scam methodology that involved redirecting the browser to a whole bunch of domains, and then onto one of a number of malicious control servers to direct the fraud itself. This involved providing different locations to which private user browsing data should be uploaded and lists of advertisements to be fed to the browser.
According to the report, authored jointly by Jamila Kaya and Duo Security information security engineer Jacob Rickerd, this primary malicious behavior resulted in users regularly getting fed new redirector domains leading to both “benign” and illegitimate advertising streams. Even though most of the ad streams fed to those users who had installed any of these Chrome web browser extensions were from “genuine” advertisers, the researchers said that what differentiated them as being malvertising ad fraud was “the large volume of ad content shown, the fact that the user does not see many if not the majority of these ads, and the fact that malicious third-party actors are actively using these streams to redirect the user to malware and phishing.”
Google responds quickly to mitigate against the threat from these malicious Chrome extensions
Once the researchers had reported their findings to Google, things escalated somewhat. The Google security team went on to identify an additional 430 Chrome web browser extensions involved. These, along with the original 70 extensions, were then removed from the Google Chrome Web Store. This is to be expected, as Google has proven to be taking a very proactive stance when it comes to matters of security.
A Google spokesperson said that “when we are alerted of extensions in the Web Store that violate our policies, we take action and use those incidents as training material to improve our automated and manual analyses.” The spokesperson also told the Duo Security researchers that Google executes “regular sweeps to find extensions using similar techniques, code, and behaviors, and take down those extensions if they violate our policies.”
Do NOT reactivate any of these extensions
IOC | Type |
---|---|
Mapstrek.com | Plugin Domain |
Mapsscout.com | Plugin Domain |
Deluxequiz.com | Plugin Domain |
Gameschill.com | Plugin Domain |
Packtrackplus.com | Plugin Domain |
Mapsvoyage.com | Plugin Domain |
Mapsfrontier.com | Plugin Domain |
Yoyoquiz.com | Plugin Domain |
Recipeally.com | Plugin Domain |
Supersimpletools.com | Plugin Domain |
playziz.com | Plugin Domain |
jumboquiz.com | Plugin Domain |
mapspilot.com | Plugin Domain |
expressdirections.com | Plugin Domain |
freeweatherapp.com | Plugin Domain |
gofreeradio.com | Plugin Domain |
lovetestpro.com | Plugin Domain |
playthunder.com | Plugin Domain |
quizflavor.com | Plugin Domain |
gamedaddio | Plugin Domain |
packagetrak.com | Plugin Domain |
Froovr | Plugin Domain |
classifiedsnearme.com | Plugin Domain |
gamezooks.com | Plugin Domain |
quicknewsplus.com | Plugin Domain |
playpopgames.com | Plugin Domain |
easytoolonline.com | Plugin Domain |
greatarcadehits.com | Plugin Domain |
crusharcade.com | Plugin Domain |
promediaconverter.com | Plugin Domain |
Arcadeyum.com | Plugin Domain |
dtsince.com | Control Domain |
comvng.com | Control Domain |
elsticsr.com | Control Domain |
gdprcountryrestriction.com | Deterministic Domain |
rowams.com | Redirector Domain |
glaulb.com | Redirector Domain |
rodmnd.com | Redirector Domain |
arpdmn.com | Redirector Domain |
fulamz.com | Redirector Domain |
rdrdmn.com | Redirector Domain |
rnddmn.com | Redirector Domain |
srvnmdom.com | Redirector Domain |
rdcnew.com | Redirector Domain |
rndmdmn.com | Redirector Domain |
amdaws.com | Redirector Domain |
fmtaws.com | Redirector Domain |
hometailer.com | Redirector Domain |
rdraws.com | Redirector Domain |
srvtop.com | Redirector Domain |
globlb.com | Redirector Domain |
frshdmn.com | Redirector Domain |
rawdws.com | Redirector Domain |
reddmn.com | Redirector Domain |
reqaws.com | Redirector Domain |
gleglb.com | Redirector Domain |
newdmn.com | Redirector Domain |
gluedc.com | Redirector Domain |
tmntho.com | Redirector Domain |
srvalgo.com | Redirector Domain |
wrrpam.com | Redirector Domain |
dmnamz.com | Redirector Domain |
rddmns.com | Redirector Domain |
Multiext.com | Local Storage Exfil Domain |
ticsync.com | End Domain |
usavisitorco.com | End Domain |
usavisitorcenter.com | End Domain |
sponsergift.pro | End Domain |
3f6i9.com | End Domain |
usaconsumerperks.com | End Domain |
rewardsecure.com | End Domain |
jenrx2u.com | End Domain |
runslin.com | End Domain |
securedgift.com | End Domain |
usasecureconsumer.com | End Domain |
usavisitorrewards.com | End Domain |
usavisitors.org | End Domain |
usapremiumclub.com | End Domain |
usaperkscenter.com | End Domain |
usagiftscenter.com | End Domain |
premiumclubusa.com | End Domain |
usaclub.vip | End Domain |
.com | TLD |
.net | TLD |
.pro | TLD |
.vip | TLD |
PackageTrak Promos | Plugin Name |
ProMediaConverter Promotions | Plugin Name |
EasyToolOnline Promos | Plugin Name |
CrushArcade Ads | Plugin Name |
GreatArcadeHits Ads | Plugin Name |
ArcadeFrontier Ads | Plugin Name |
MapsFrontier Advertising | Plugin Name |
SuperSimpleTools Promos | Plugin Name |
Advertisements by ArcadeYum | Plugin Name |
PackTrackPlus Promos | Plugin Name |
EasyToolOnline Promos | Plugin Name |
PlayPopGames Ads | Plugin Name |
QuickNewsPlus Promos | Plugin Name |
GameZooks Advertisements | Plugin Name |
PackTrackPlus Promotions | Plugin Name |
PackTrackPlus Promotions | Plugin Name |
MapsFrontier Advertisement Offers | Plugin Name |
ExpressDirections Promos | Plugin Name |
MapsTrek Promos | Plugin Name |
ClassifiedsNearMe Promos | Plugin Name |
MapsTrek Promos | Plugin Name |
ClassifiedsNearMe Promos | Plugin Name |
ExpressDirections Promos | Plugin Name |
MapsTrek Offers | Plugin Name |
MapsVoyage Promotions | Plugin Name |
FreeWeatherApp Promotions | Plugin Name |
EarthViewDirections Promotions | Plugin Name |
MapsFrontier Advertisements | Plugin Name |
ArcadeCookie Offers | Plugin Name |
RecipeAlly Promos | Plugin Name |
MapsTrek Promotions | Plugin Name |
Offers by MapsFrontier | Plugin Name |
GamesChill Ads | Plugin Name |
PackTrackPlus Promotions | Plugin Name |
MapsVoyage Ads | Plugin Name |
Advertising by MapsFrontier | Plugin Name |
PlayZiz Advertisements | Plugin Name |
Advertising Offers by MapsVoyage | Plugin Name |
MapsFrontier Advertising Offers | Plugin Name |
FreeWeatherApp Promos | Plugin Name |
FreeWeatherApp Advertisement Offers | Plugin Name |
ExpressDirections Ads | Plugin Name |
YoYoQuiz Promotions | Plugin Name |
MapsVoyage Advertising | Plugin Name |
MapsPilot Ad Offers | Plugin Name |
GoFreeRadio Promos | Plugin Name |
Advertising Offers by FreeWeatherApp | Plugin Name |
Advertisement Offers by QuizKicks | Plugin Name |
Ads by MapsVoyage | Plugin Name |
JumboQuiz Advertising | Plugin Name |
MapsScout Advertising Offers | Plugin Name |
DeluxeQuiz Advertising | Plugin Name |
SuperSimpleTools Promos | Plugin Name |
Advertising by MapsPilot | Plugin Name |
Advertisements by MapsScout | Plugin Name |
PackageTrak Promos | Plugin Name |
Ad offers by Froovr | Plugin Name |
PackageTrak Promos | Plugin Name |
GameDaddio Marketing | Plugin Name |
DearQuiz Advertising | Plugin Name |
Offers by MapsScout | Plugin Name |
YoYoQuiz Advertisements | Plugin Name |
Advertisment Offers by GameDaddio | Plugin Name |
QuizFlavor Advertising | Plugin Name |
Advertisements by QuizDiamond | Plugin Name |
QuizPremium Advertisements | Plugin Name |
CouponRockstar Offers | Plugin Name |
MapsFrontier Promos | Plugin Name |
Advertising Offers by MapsPilot | Plugin Name |
PlayThunder Offers | Plugin Name |
LoveTestPro Ad Offers | Plugin Name |
oanbpfkcehelcjjipodkaafialmfejmi | Plugin ID |
lhfibgclamcffnddoicjmoopmgomknmb | Plugin ID |
ilcbbngkolbclhlildojhgjdbkkehfia | Plugin ID |
pnhjnmacgahapmnnifmneapinilajfol | Plugin ID |
ocifcogajbgikalbpphmoedjlcfjkhgh | Plugin ID |
peglehonblabfemopkgmfcpofbchegcl | Plugin ID |
aaeohfpkhojgdhocdfpkdaffbehjbmmd | Plugin ID |
lidnmohoigekohfmdpopgcpigjkpemll | Plugin ID |
jmbmildjdmppofnohldicmnkojfhggmb | Plugin ID |
jdoaaldnifinadckcbfkbiekgaebkeif | Plugin ID |
ogjfhmgoalinegalajpmjoliipdibhdm | Plugin ID |
lebmkjafnodbnhbahbgdollaaabcmpbh | Plugin ID |
gjammdgdlgmoidmdfoefkeklnhmllpjp | Plugin ID |
kdkpllchojjkbgephbbeacaahecgfpga | Plugin ID |
jaehldonmiabhfohkenmlimnceapgpnp | Plugin ID |
pmhlkgkblgeeigiegkmacefjoflennbn | Plugin ID |
ofdfbeanbffehepagohhengmjnhlkich | Plugin ID |
mjchijabihjkhmmaaihpgmhkklgakinl | Plugin ID |
poppendnaoonepbkmjejdfebihohaalo | Plugin ID |
eogoljjmndnjfikmcbmopmlhjnhbmdda | Plugin ID |
gdnkjjhpffldmfljpbfemliidkeeecdj | Plugin ID |
gelcjfdfebnabkielednfoogpbhdeoai | Plugin ID |
ofpihhkeakgnnbkmcoifjkkhnllddbld | Plugin ID |
pjjghngpidphgicpgdebpmdgdicepege | Plugin ID |
nchdkdaknojhpimbfbejfcdnmjfbllhj | Plugin ID |
blcfpeooekoekehdpbikibeblpjlehlh | Plugin ID |
looclnmoilplejheganiloofamfilbcd | Plugin ID |
oehimkphpeeeneindfeekidpmkpffkgc | Plugin ID |
eebbihndkbkejmlgfoofigacgicamfha | Plugin ID |
faopefnnleiebimhkldlplkgkjpbmcea | Plugin ID |
obcfkcpejehknjdollnafpebkcpkklbl | Plugin ID |
jepocknhdcgdmbiodbpopcbjnlgecdhf | Plugin ID |
dehhfjanlmglmabomenmpjnnopigplae | Plugin ID |
ekijhekekfckmkmbemiijdkihdibnbgh | Plugin ID |
pjpjefgijnjlhgegceegmpecklonpdjp | Plugin ID |
nlhocomjnfjedielocojomgfldbjmdjj | Plugin ID |
opooaebceonakifaacigffdhogdgfadg | Plugin ID |
ojofdaokgfdlbeomlelkiiipkocneien | Plugin ID |
gpaaalbnkccgmmbkendiciheljgpdhob | Plugin ID |
almfnpjmjpnknlgpipillhfmchjikkno | Plugin ID |
eeacchjlmkcleifpppcjbmahcnlihamj | Plugin ID |
lojgkcienjoiogbfkbjiidpfnabhkckf | Plugin ID |
gkemhapalomnipjhminflfhjcjehjhmp | Plugin ID |
icolkoeolaodpjogekifcidcdbgbdobc | Plugin ID |
abjbfhcehjndcpbiiagdnlfolkbfblpb | Plugin ID |
bbjilncoookdcjjnkcdaofiollndepla | Plugin ID |
igpcgjcdhmdjhdlgoncfnpkdipanlida | Plugin ID |
nfhpojfdhcdmimokleagkdcbkmcgfjkh | Plugin ID |
jfnlkmaledafkdhdokgnhlcmeamakham | Plugin ID |
dibjpjiifnahccnokciamjlfgdlgimmn | Plugin ID |
fjclfmhapndgeabdcikbhemimpijpnah | Plugin ID |
jpnamljnefhpbpcofcbonjjjkmfjbhdp | Plugin ID |
iggmbfojpkfikoahlfghaalpbpkhfohc | Plugin ID |
fkllfgoempnigpogkgkgmghkchmjcjni | Plugin ID |
dealfjgnmkibkcldkcpbikenmajlglmc | Plugin ID |
abghmipjfclfpgmmelbgolfgmhnigbma | Plugin ID |
dcbfmglfdlgpnolgdjoioeocllioebpe | Plugin ID |
obmbmalbahpfbckpcfbipooimkldgphm | Plugin ID |
gbkmkgfjngebdcpklbkeccelcjaobblk | Plugin ID |
ehibgcefkpbfkklbpahilhicidnhiboc | Plugin ID |
gmljddfeipofcffbhhcpohkegndieeab | Plugin ID |
dajgdhiemoaecngkpliephmheifopmjb | Plugin ID |
fdbmoflclpmkmeobidcgmfamkicinnlg | Plugin ID |
obbfndpanmiplgfcbeonoocobbnjdmdc | Plugin ID |
lgljionbhcfbnpjgfnhhoadpdngkmfnh | Plugin ID |
ddenjpheppdmfimooolgihimdgpilhfo | Plugin ID |
bblkckhknhmalchbceidkmjalmcmnkfa | Plugin ID |
fhkmacopackahlbnpcfijgphgoimpggb | Plugin ID |
eohnfgagodblipmmalphhfepaonpnjgk | Plugin ID |
emkkigmmpfbjmikfadmfeebomholoikg | Plugin ID |
fekjbjbbdopogpamkmdjpjicapclgamj | Plugin ID |
ff6f8c062bb9b4b66de6929ff2921f5fd9eff4b013b32842e9e7e51f609c1f0f | SHA256 Hash |
0c1a8ca8ad72db5c0c3babc8d2488cc4ac7815d8158d170c5fd4c1056cd7dd87 | SHA256 Hash |
68707cfc2c7bfe721e22f681c86480c012ce7b28f442c2e0090fde95663b6f13 | SHA256 Hash |
Maps | Plugin Name Pattern |
Promos | Plugin Name Pattern |
Pack | Plugin Name Pattern |
Plus | Plugin Name Pattern |
Ad | Plugin Name Pattern |
Advertising | Plugin Name Pattern |
Offers | Plugin Name Pattern |
Quiz | Plugin Name Pattern |
Marketing | Plugin Name Pattern |
Promotions | Plugin Name Pattern |
Advertisements | Plugin Name Pattern |
Scz?p= | Redirector URI Pattern |
Fzs?p= | Redirector URI Pattern |
About Author
Discover more from BillionBill
Subscribe to get the latest posts sent to your email.