← Terug naar overzicht

Socket Threat Research identified 19 malicious browser extensions (18 Chrome, 1 Edge) delivering an extendable malware framework tracked as the 'Superior' campaign, active since February 2024. The extensions use WebSocket C2 communication, CSP stripping, and XSS injection to execute malicious payloads. Key capabilities include multi-chain wallet draining (EVM, Solana, Tron), hardware wallet seed-phrase phishing for Trezor and Ledger, credential harvesting from major crypto exchanges, universal form grabbing, social media token theft, browser history exfiltration, and ClickFix fake-update lures. A critical tactic involves acquiring legitimate extensions with existing user bases and weaponizing them, with one extension affecting up to 80,000 users. The malware uses AES-GCM encryption for C2 communications and supports C2 rotation for resilience. The campaign has been operational for over two years and has expanded from Chrome to Microsoft Edge.

Affected products

  • Allow Copy - Select & Enable Right Click
  • Blockfolio: Address Monitor
  • Creative Library - Ad Spy Tool
  • Crypto Alerter: Price Alarms & Volatility Warnings
  • Crypto Price Badge: Quick Glance
  • Crypto Rates & Fiat Converter
  • DeFi Pulse Tracker
  • Enable Right Click & Copy — Smart Unlock + OCR
  • Google Chrome
  • LedgerLook: Wallet Checker
  • Meta & Facebook Ad Library Spy — FeedX-Ray
  • Microsoft Edge
  • Multi-Chain Explorer
  • Password Protect PDF
  • PixelCheck
  • Private Crypto News Reader
  • QuickLens - Search Screen with Google Lens
  • RapidLens - Google Lens for Screen Search & Images
  • SEO Pulse Pro
  • Site Signal - Website Traffic & SEO Checker
  • Website Traffic Checker: MirrorSphere SEO Stats

Related threat actors

  • Superior Campaign

IOC's

active-enable-right-click[.]top, api[.]enable-right-click[.]click, enable-right-click[.]click, payload[.]siteinsight[.]bond, api[.]extensionanalyticspro[.]top, password-protect-pdf[.]com, privatecryptonewsreader[.]pro, cryptoratesfiatconverter[.]pro, cryptopricebadgequickglance[.]pro, ws[.]site-signal[.]top, content[.]resonanceweb[.]top, api[.]creativelibrary[.]top, api[.]codefilearc[.]net, ws[.]seopulsepro[.]sbs, relay[.]seopulsepro[.]sbs, defipulsetracker[.]pro, blockfolioaddressmonitor[.]pro, pricealarmsvolatilitywarnings[.]pro, extension[.]io-safe[.]icu, feedback[.]feedx-ray[.]top, lucky-random[.]sbs, pipi[.]saghirmohamed19[.]workers[.]dev, mimi[.]saghirmohamed19[.]workers[.]dev, cookie-whitelist[.]top, whale-alert[.]art, ggle-analytics[.]com, pkoccklolohdacbfooifnpebakpbeipc, fegckejpfnlmfgkfjpinlbgmeeijjkel, kdenlnncndfnhkognokgfpabgkgehodd, jamminefolhgepgihbmcjjhgldbfcikp, inmkjedjdhgpknjogbjomhnbgdccckkg, fcgdejjichpgfaaafflplhfijcnieopb, cfpnjdbpojpcongfaefcamjbaolpelcd, aapdalkmclfaahehnmicbglkohkldhne, dkdadldmiefjldmegbjbnhhfddnkhlhm, fjmlhlkccegopebcllcmafahkmeejpph, iekoapohahgmogbagegmcgplbkikcgke, ahpnnnjbnfbhoikhohglpohnoocjcoco, oeacadlaclegkkkdehjmiifnjhcekclj, jmlgannjlbliikgcaieomgmcnfplglea, lhmcajhgadanidbopgaoobjlldegjmke, gfackggoapepdmnjnkblogdcjpgcjiak, hfijkbdkpidafdbeebnnkhfccildbcle, pcngchfbfgejllcbhmeadjhiebebiome, aodkjdeghbjiaienipfjkbpcikkacbcp

Categories

  • Data Breach & Exfiltration
  • Identity & Access
  • Ransomware & Malware
  • Web Technologies

Related links