108 Coordinated Chrome Extensions Hijack Your Private Telegram Sessions
ID: eb8971bc-6e60-50fc-99fc-f17044aa8153
STIX ID: report--eb8971bc-6e60-50fc-99fc-f17044aa8153
Feed Name: securityonline.info
Socket’s Threat Research Team identified a professional-grade campaign of 108 malicious Chrome extensions (~20,000 installs) published under multiple developer names that all communicate with a common C2 (cloudapi.stream). The extensions provide legitimate-looking functionality (Telegram sidebar, games, enhancers) while stealthily stealing Telegram Web sessions (polled every 15s), harvesting Google account identity via OAuth2, and maintaining persistence via a loadInfo() backdoor that silently opens attacker-controlled URLs; evidence (shared OAuth client IDs, Russian debug strings, embedded support email) indicates unified ownership and active exploitation, and takedown requests to Google are in progress.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
