The Case of Cloud9 Chrome Botnet
ID: a22a6513-adfc-5ed6-94fd-62da65cea500
STIX ID: report--a22a6513-adfc-5ed6-94fd-62da65cea500
Feed Name: Zimperium Blog
Threat Score
Cloud9 is a malicious browser-extension JavaScript botnet (distributed via hacker forums, fake installers and malicious sites) that acts as a remote access trojan and infostealer: it steals cookies, keystrokes and clipboard contents, performs cryptomining and HTTP POST traffic for Layer-7 attacks, and uses browser exploits (multiple CVEs) to drop Windows malware; the report includes technical behavior, exploitation details, distribution context, and IoCs (IPs, domains, hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
