12 Fraudulent Browser Extensions Disguised as TikTok Downloaders Compromise 130K Users
ID: 1e2d8dd7-1553-5d05-8089-779e98fb7228
STIX ID: report--1e2d8dd7-1553-5d05-8089-779e98fb7228
Feed Name: GBHackers
LayerX Security disclosed a large, organized campaign of malicious Chrome and Edge extensions posing as TikTok downloaders that have infected over 130,000 users (≈12,500 active). The extensions use a shared Manifest V3 codebase and fetch remote JSON configurations from typosquatted domains to change behavior at runtime, enable delayed malicious capabilities months after installation, and harvest high-entropy telemetry (including battery status and locale data) for persistent user fingerprinting; defenders are advised to implement continuous, behavior-based monitoring to detect anomalous network activity, permissions use, and DOM interactions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
