Threat Intelligence Feeds and Endpoint Protection Systems Fail to Detect 24 Malicious Chrome Extensions
ID: a2a5f308-5ddc-57aa-bdea-e2f9013221c3
STIX ID: report--a2a5f308-5ddc-57aa-bdea-e2f9013221c3
Feed Name: Cato Networks
Cato Research Labs analyzed network telemetry from hundreds of customers and identified 85 malicious Chrome extensions and 40 domains—many previously undetected by endpoint protection and threat intelligence—which perform activities from adware to credential theft and C&C communications; the report provides extension IDs and domains, details distribution and evasion techniques (fake Web Store uploads, malicious updates, extension takeovers), demonstrates a fake Postman extension used to steal credentials, and recommends whitelisting, permission review, browser security hardening, and network-based C&C detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
