logo

Decoy Manuals and Malicious Browser Extensions: A Closer Look at a Multi-Layered Threat

ID: 416b54dc-e2cc-539f-be5d-9fb46802ad5a

STIX ID: report--416b54dc-e2cc-539f-be5d-9fb46802ad5a

Feed Name: Hunt.io Blog

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

The report describes an investigation of an open directory hosting a malicious Windows executable (protect_distribution.exe/Acrobat.exe) and two Chrome extensions (browser-extension.crx and xl_ext_chrome.crx) derived from an open-source extension-code-injector project; the actor used registry modifications and scheduled tasks to silently install the extension, enabling browser surveillance (fingerprinting, screenshots, potential keystroke/form capture) and communicating with a hardcoded C2 (61978k512k.goho.co). The analysis provides dynamic and static findings, PowerShell scripts used for persistence and allowlisting, strings suggesting PyInstaller, code comments in Chinese indicating active development, and a table of network and host observables (IPs, domains, filenames, SHA-256 hashes) to support detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.