logo

Chrome Extension Steals Credentials of Bank Customers

ID: bf169855-5e8b-5fb2-93e7-e2a86f73b248

STIX ID: report--bf169855-5e8b-5fb2-93e7-e2a86f73b248

Feed Name: Zscaler Security Research Blog

Threat Score
74/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This analysis details a Delphi Trojan that drops and activates a malicious Chrome extension (masquerading as "Google Secure Web") to steal cookies and login credentials from Banco do Brasil customers. The malware downloads obfuscated extension files, alters Chrome shortcuts to load the extension, disables Chrome's developer-mode warnings via a batch script, sets a malicious proxy to route victim traffic through attacker infrastructure, injects scripts to intercept specific bank login actions, exfiltrates session cookies and captured credentials to attacker-controlled endpoints, and includes MD5 hashes and network IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.