GhostPoster Malware Targets Chrome Users via 17 Rogue Extensions
ID: 34d30266-219f-5369-9183-0596c6bf0e74
STIX ID: report--34d30266-219f-5369-9183-0596c6bf0e74
Feed Name: GBHackers
A long-running, sophisticated campaign named GhostPoster deployed 17 malicious Chrome, Firefox, and Edge extensions (collectively >840,000 installs) that embed initial loaders inside PNG icon files using steganography. Extensions implement delayed activation (48 hours to ~5 days), contact remote C2 to fetch modular JavaScript payloads, strip/inject HTTP headers to weaken CSP/HSTS, and perform affiliate traffic hijacking, click fraud, tracking, and CAPTCHA bypass; IOCs and removal recommendations are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
