Researchers Expose New Polymorphic Attack That Clones Browser Extensions to Steal Credentials

Researchers in cybersecurity have shown a new method that enables a malicious web browser extension to mimic any installed add-on.

According to a report released last week by SquareX, “the polymorphic extensions make an exact duplicate of the target’s icon, HTML popup, workflows, and even temporarily disables the legitimate extension, making it very convincing for victims to believe that they are providing credentials to the real extension.”

Threat actors might then misuse the credentials they have stolen to take over internet accounts and obtain private financial and personal data without authorization. All Chromium-based web browsers, such as Google Chrome, Microsoft Edge, Brave, Opera, and others, are vulnerable to the assault.

The strategy relies on people often pinning extensions to the toolbar of their browsers read more about Researchers Expose New Polymorphic Attack That Clones Browser Extensions to Steal Credentials.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *