Malicious Chrome Extensions as VPN Intercept User Traffic to Steal Credentials
ID: 05ef522f-a162-52a7-a017-a3ab9f6a8f59
STIX ID: report--05ef522f-a162-52a7-a017-a3ab9f6a8f59
Feed Name: cybersecurityNews.com
Two malicious Chrome extensions marketed as VPN/proxy “Phantom Shuttle” have been distributed via the Chrome Web Store to over 2,180 users; they perform real proxy/latency functions while covertly intercepting HTTP authentication, injecting hardcoded proxy credentials, and exfiltrating plaintext email/passwords and other browsing data to a C2 (phantomshuttle.space) on a regular heartbeat—researchers observed obfuscated JS, use of chrome.webRequest.onAuthRequired in asyncBlocking mode, and continuous credential theft prompting takedown requests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
