Attack of The Extensions
SpecterOps demonstrates how attackers can silently side-load Chromium extensions to establish browser-resident C2 channels, enabling persistent cookie theft that evades most endpoint controls.
Summary written by editorial AI · Source link below
TL;DR: Browser extensions can turn Chromium into a persistent foothold. This post introduces a way to silently install extensions turning Chromium browsers into a command and control (C2) platform for persistent cookie theft. Intro This blog is a continuation of Dough No! Revisiting Cookie Theft. In the previous blog, we looked at how Chromium’s Application […] The post Attack of The Extensions appeared first on SpecterOps .
Editorial Analysis
Browser-based C2 persistence evades traditional EDR and proxy controls; enterprises relying on Chromium without extension allow-lists face a blind spot that attackers are now actively weaponising.
Enforce a strict Chromium extension allow-list via Group Policy and monitor for unsigned or developer-mode extension installations.
Browsers can be silently turned into attacker footholds; extension allow-listing is a low-cost control that closes this gap.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at SpecterOps in a new tab.
More from the Research Desk
- 39 New Methods That Compromise Passkey Authentication3d
- Security Vulnerability in a Voting System3d
- Selfie-Capture Dynamics as an Auxiliary Signal Against Deepfakes and Injection Attacks for Mobile Identity Verification4d
- How Reliable Is the Multi-Input Heuristic for Bitcoin Address Clustering in Law Enforcement Contexts?4d
- Privacy Leakage in Federated Learning: Gradient-Based Client Identity Inference and Defenses for Inertial Sensing in Vehicular Edge Networks4d