logo

Cyberhaven Extension Compromise: TLS Certificates Reveal Hidden Infrastructure

ID: 6546734b-396d-566f-8b17-b75b9e2b77e6

STIX ID: report--6546734b-396d-566f-8b17-b75b9e2b77e6

Feed Name: Hunt.io Blog

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

In December 2024 a phishing-driven compromise of a Chrome extension allowed a malicious update to exfiltrate cookies and session data; researchers pivoted on a recurring Let's Encrypt TLS certificate to identify a cluster of ~19 servers (mostly on Vultr/The Constant Company), enumerate many domains/IPs used as C2 or infrastructure, and surface IoCs that indicate a long-running, financially motivated campaign possibly targeting Facebook advertising accounts, although definitive attribution is not established.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.