A new malware service promises to skip Google’s review process and get your malware straight onto the Chrome Store



  • Russian hackers sell Chrome extension service that bypasses Google Store moderation
  • Malicious add-on spoofs legitimate sites with full-screen iframes to steal credentials
  • Varonis advises strict enterprise allowlisting and consumer extension audits for protection

Russian hackers are selling a service that allows other criminals to spoof legitimate websites, tricking victims into exposing login credentials, or possibly even making fraudulent wire transfers.

A threat actor alias ‘Stenli’ (Stanley) recently started offering a service which basically guarantees that a malicious Chrome extension will “pass Google Store moderation” and land in the browser’s add-on repository.


https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-2000-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img