logo

Malware force-installs Chrome extensions on 300,000 browsers, patches DLLs

ID: b067f50d-fa5c-553e-9e34-74b9c56dba9d

STIX ID: report--b067f50d-fa5c-553e-9e34-74b9c56dba9d

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-08-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

An ongoing, large-scale campaign uses digitally signed fake installers and PowerShell scripts to force-install malicious Google Chrome and Microsoft Edge extensions in over 300,000 browsers; these extensions hijack searches, steal browsing history and credentials, and persist by creating scheduled tasks, adding registry policies, modifying browser shortcuts and DLLs to prevent updates and hide from extension managers. ReasonLabs and BleepingComputer documented the IOCs, listed affected extensions, and provided manual cleanup guidance including removing scheduled tasks, registry ForceInstall entries, and the malicious PowerShell files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.