Decoy Manuals and Malicious Browser Extensions: A Closer Look at a Multi-Layered Threat
ID: 416b54dc-e2cc-539f-be5d-9fb46802ad5a
STIX ID: report--416b54dc-e2cc-539f-be5d-9fb46802ad5a
Feed Name: Hunt.io Blog
The report describes an investigation of an open directory hosting a malicious Windows executable (protect_distribution.exe/Acrobat.exe) and two Chrome extensions (browser-extension.crx and xl_ext_chrome.crx) derived from an open-source extension-code-injector project; the actor used registry modifications and scheduled tasks to silently install the extension, enabling browser surveillance (fingerprinting, screenshots, potential keystroke/form capture) and communicating with a hardcoded C2 (61978k512k.goho.co). The analysis provides dynamic and static findings, PowerShell scripts used for persistence and allowlisting, strings suggesting PyInstaller, code comments in Chinese indicating active development, and a table of network and host observables (IPs, domains, filenames, SHA-256 hashes) to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
