logo

Genesis Market - Malicious Browser Extension

ID: 547def11-7c8e-586e-b376-7fb01d8ae2b2

STIX ID: report--547def11-7c8e-586e-b376-7fb01d8ae2b2

Feed Name: Cybereason Blog

Threat Score
78/100

Date Published: 2025-05-21

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

Cybereason GSOC analyzed a LummaStealer campaign that installs a malicious Genesis Market browser extension via a multi-stage installer (ZIP -> MSI -> DLL -> obfuscated PowerShell). The extension targets Chrome, Edge, Brave and Opera to collect cookies, clipboard, payment and crypto data, screenshots, emails (including 2FA codes), installed extensions and filesystem artifacts, communicates with attacker C2s (resolved via blockchain transactions and WebSocket reverse proxies), and provides persistence and remote control; the report includes IoCs, MITRE mappings and containment/remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.