Fake Bitwarden ads on Facebook push info-stealing Chrome extension
ID: 506b52be-ae47-53c5-b562-e40aedbcf8df
STIX ID: report--506b52be-ae47-53c5-b562-e40aedbcf8df
Feed Name: Bleeping Computer
Bitdefender Labs observed a malicious Facebook ad campaign (launched Nov 3, 2024) impersonating Bitwarden that lures users to a fake Chrome Web Store page which instructs them to download and sideload a ZIP-hosted Chrome extension. When manually installed in developer mode, the extension registers as “Bitwarden Password Manager” and harvests Facebook cookies (including c_user), account and billing information via the Graph API, IP/geolocation, and other sensitive browser data before exfiltrating encoded data to attacker-controlled Google Script URLs; users are advised to only install extensions from the official Chrome Web Store and vendor sites.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
