A malicious Chrome extension posing as GoogleTranslate enables threat actors to steal sensitive information, live-stream web sessions, and remotely interact with Chrome windows without being detected. VMRay researchers discovered that the binary drops a malicious Chrome extension alongside an AutoIt script, which subsequently deploys Stealcv2 for stealing information. Such information can help attackers hijack online accounts, bypass session-based protections, profile victims, and identify high-value services such as email, cryptocurrency platforms, cloud consoles, and corporate applications.
The most concerning capability is its ability to provide attackers with a real-time view of Chrome windows and let them operate websites remotely using mouse clicks and keyboard input. Extensions can interact with tabs and may access sensitive tab properties or inject scripts into matching websites when granted relevant permissions.
This technique minimizes the likelihood that a user will notice unauthorized clicks, navigation, or form submissions happening concurrently with their work within another application or window. Organizations should restrict unmanaged extensions, monitor for suspicious browser-policy changes, and require phishing-resistant multi-factor authentication to mitigate the damage from stolen passwords and session data. IoCs IoC Type IoC Details Associated Component Command-and-Control Server http[:]//87.120.104[.
]147:8080 Suspected attacker-controlled infrastructure Command-and-Control Server http[:]//160.20.109[. ]33:80 Suspected attacker-controlled infrastructure SHA-256 Hash 7ba2c663d76d2d353a02d815381f22a1b04b2032162b1559455d1f456432340a Rust-based initial binary/loader SHA-256 Hash 02e9da11f035bd4e18338ddd78e2818da49e7d1c8f614e9b329afaf581c33301 Fake GoogleTranslate Chrome extension SHA-256 Hash 4f82542f68d2e677fb64ba986c8d5f3a04017a1bf7a11d375e52f950e32eb262 AutoIt script SHA-256 Hash 45c7d791fab4128fb495f359ed641e217883f132bb8f13c1e181caf5f5279a34 Stealc v2 information stealer












