logo

Rilide - An Information Stealing Browser Extension

ID: 744a835c-2301-58b6-ac92-556c49fddf0f

STIX ID: report--744a835c-2301-58b6-ac92-556c49fddf0f

Feed Name: Pulsedive Blog

Threat Score
72/100

Date Published: 2025-03-21

Date Updated: 2026-04-28

Author: Pulsedive Threat Research

...
...

Rilide is an information-stealing malware masquerading as a browser extension (often impersonating Google Drive) that targets Chromium-based browsers to capture screenshots, log credentials (including cryptocurrency wallets), manipulate web pages/emails, and exfiltrate data to a C2 resolved via blockchain-based dead drops; the report provides a multi-stage PowerShell dropper analysis, file/manifest contents, network IoCs, MITRE ATT&CK mappings, and mitigations including extension management and PowerShell logging.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.