logo

108 Coordinated Chrome Extensions Hijack Your Private Telegram Sessions

ID: eb8971bc-6e60-50fc-99fc-f17044aa8153

STIX ID: report--eb8971bc-6e60-50fc-99fc-f17044aa8153

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-15

Date Updated: 2026-04-23

Author: Ddos

...
...

Socket’s Threat Research Team identified a professional-grade campaign of 108 malicious Chrome extensions (~20,000 installs) published under multiple developer names that all communicate with a common C2 (cloudapi.stream). The extensions provide legitimate-looking functionality (Telegram sidebar, games, enhancers) while stealthily stealing Telegram Web sessions (polled every 15s), harvesting Google account identity via OAuth2, and maintaining persistence via a loadInfo() backdoor that silently opens attacker-controlled URLs; evidence (shared OAuth client IDs, Russian debug strings, embedded support email) indicates unified ownership and active exploitation, and takedown requests to Google are in progress.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.