logo

GhostPoster Malware Targets Chrome Users via 17 Rogue Extensions

ID: 34d30266-219f-5369-9183-0596c6bf0e74

STIX ID: report--34d30266-219f-5369-9183-0596c6bf0e74

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-19

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A long-running, sophisticated campaign named GhostPoster deployed 17 malicious Chrome, Firefox, and Edge extensions (collectively >840,000 installs) that embed initial loaders inside PNG icon files using steganography. Extensions implement delayed activation (48 hours to ~5 days), contact remote C2 to fetch modular JavaScript payloads, strip/inject HTTP headers to weaken CSP/HSTS, and perform affiliate traffic hijacking, click fraud, tracking, and CAPTCHA bypass; IOCs and removal recommendations are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.