Socket Threat Research identified 19 malicious browser extensions (18 Chrome, 1 Edge) delivering an extendable malware framework tracked as the 'Superior' campaign, active since February 2024. The extensions use WebSocket C2 communication, CSP stripping, and XSS injection to execute malicious payloads. Key capabilities include multi-chain wallet draining (EVM, Solana, Tron), hardware wallet seed-phrase phishing for Trezor and Ledger, credential harvesting from major crypto exchanges, universal form grabbing, social media token theft, browser history exfiltration, and ClickFix fake-update lures. A critical tactic involves acquiring legitimate extensions with existing user bases and weaponizing them, with one extension affecting up to 80,000 users. The malware uses AES-GCM encryption for C2 communications and supports C2 rotation for resilience. The campaign has been operational for over two years and has expanded from Chrome to Microsoft Edge.
active-enable-right-click[.]top, api[.]enable-right-click[.]click, enable-right-click[.]click, payload[.]siteinsight[.]bond, api[.]extensionanalyticspro[.]top, password-protect-pdf[.]com, privatecryptonewsreader[.]pro, cryptoratesfiatconverter[.]pro, cryptopricebadgequickglance[.]pro, ws[.]site-signal[.]top, content[.]resonanceweb[.]top, api[.]creativelibrary[.]top, api[.]codefilearc[.]net, ws[.]seopulsepro[.]sbs, relay[.]seopulsepro[.]sbs, defipulsetracker[.]pro, blockfolioaddressmonitor[.]pro, pricealarmsvolatilitywarnings[.]pro, extension[.]io-safe[.]icu, feedback[.]feedx-ray[.]top, lucky-random[.]sbs, pipi[.]saghirmohamed19[.]workers[.]dev, mimi[.]saghirmohamed19[.]workers[.]dev, cookie-whitelist[.]top, whale-alert[.]art, ggle-analytics[.]com, pkoccklolohdacbfooifnpebakpbeipc, fegckejpfnlmfgkfjpinlbgmeeijjkel, kdenlnncndfnhkognokgfpabgkgehodd, jamminefolhgepgihbmcjjhgldbfcikp, inmkjedjdhgpknjogbjomhnbgdccckkg, fcgdejjichpgfaaafflplhfijcnieopb, cfpnjdbpojpcongfaefcamjbaolpelcd, aapdalkmclfaahehnmicbglkohkldhne, dkdadldmiefjldmegbjbnhhfddnkhlhm, fjmlhlkccegopebcllcmafahkmeejpph, iekoapohahgmogbagegmcgplbkikcgke, ahpnnnjbnfbhoikhohglpohnoocjcoco, oeacadlaclegkkkdehjmiifnjhcekclj, jmlgannjlbliikgcaieomgmcnfplglea, lhmcajhgadanidbopgaoobjlldegjmke, gfackggoapepdmnjnkblogdcjpgcjiak, hfijkbdkpidafdbeebnnkhfccildbcle, pcngchfbfgejllcbhmeadjhiebebiome, aodkjdeghbjiaienipfjkbpcikkacbcp