logo

The Case of Cloud9 Chrome Botnet

ID: a22a6513-adfc-5ed6-94fd-62da65cea500

STIX ID: report--a22a6513-adfc-5ed6-94fd-62da65cea500

Feed Name: Zimperium Blog

Threat Score
75/100

Date Published: 2022-11-08

Date Updated: 2026-05-01

...
...

Cloud9 is a malicious browser-extension JavaScript botnet (distributed via hacker forums, fake installers and malicious sites) that acts as a remote access trojan and infostealer: it steals cookies, keystrokes and clipboard contents, performs cryptomining and HTTP POST traffic for Layer-7 attacks, and uses browser exploits (multiple CVEs) to drop Windows malware; the report includes technical behavior, exploitation details, distribution context, and IoCs (IPs, domains, hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.