SAN FRANCISCO: A newly discovered spyware effort attacked users through 32 million downloads of extensions to Google’s market-leading Chrome web browser, researchers at Awake Security told Reuters, highlighting the tech industry’s failure to protect browsers as they are used more for email, payroll and other sensitive functions.
Alphabet Inc’s Google said it removed more than 70 of the malicious add-ons from its official Chrome Web Store after being alerted by researchers last month.
“When we are alerted of extensions in the Web Store that violate our policies, we take action and use those incidents as training material to improve our automated and manual analyses,”
Google spokesman Scott Westover told Reuters.
Most of the free extensions purported to warn users about questionable websites or conversion of files from one format to another.
Instead, they siphoned off browsing history and data that provided credentials for access to internal business tools.
Based on the number of downloads, it was the most far-reaching malicious Chrome store campaign to date, according to Awake co-founder and chief scientist Gary Golomb.
Google declined to discuss how the latest spyware compared with prior campaigns, the breadth of the damage, or why it did not detect and remove the bad extensions on its own despite past promises to supervise offerings more closely. It is unclear who was behind the effort to distribute the malware. Awake said the developers supplied fake contact information when they submitted the extensions to Google.
“Anything that gets you into somebody’s browser or email or other sensitive areas would be a target for national espionage as well as organised crime,” said former National Security Agency engineer Ben Johnson, who founded security companies Carbon Black and Obsidian Security.
The extensions were designed to avoid detection by antivirus companies or security software that evaluates the reputations of web domains, Golomb said.
If someone used the browser to surf the web on a home computer, it would connect to a series of websites and transmit information, the researchers found. Anyone using a corporate network, which would include security services, would not transmit the sensitive information or even reach the malicious versions of the websites.
“This shows how attackers can use extremely simple methods to hide, in this case, thousands of malicious domains,” Golomb said.
After this story’s publication, Awake released its research, including the list of domains and extensions. https://awakesecurity.com/blog/the-internets-new-arms-dealers-malicious-domain-registrars/ All of the domains in question, more than 15,000 linked to each other in total, were purchased from a small registrar in Israel, Galcomm, known formally as CommuniGal Communication Ltd.
Awake said Galcomm should have known what was happening.
In an email exchange, Galcomm owner Moshe Fogel told Reuters that his company had done nothing wrong.
“Galcomm is not involved, and not in complicity with any malicious activity whatsoever,” Fogel wrote. “You can say exactly the opposite, we cooperate with law enforcement and security bodies to prevent as much as we can.”
Fogel said there was no record of the inquiries Golomb said he made in April and again in May to the company’s email address for reporting abusive behaviour, and he asked for a list of suspect domains.
Reuters sent him that list three times without getting a substantive response.
The Internet Corp for Assigned Names and Numbers, which oversees registrars, said it had received few complaints about Galcomm over the years, and none about malware.
While deceptive extensions have been a problem for years, they are getting worse. They initially spewed unwanted advertisements, and now are more likely to install additional malicious programmes or track where users are and what they are doing for government or commercial spies.
Malicious developers have been using Google’s Chrome Store as a conduit for a long time. After one in 10 submissions was deemed malicious, Google said in 2018 https://blog.chromium.org/2018/10/trustworthy-chrome-extensions-by-default.html it would improve security, in part by increasing human review.
But in February, independent researcher Jamila Kaya and Cisco Systems’ Duo Security uncovered https://duo.com/labs/research/ crxcavator-malvertising-2020 a similar Chrome campaign that stole data from about 1.7 million users. Google joined the investigation and found 500 fraudulent extensions.
“We do regular sweeps to find extensions using similar techniques, code and behaviours,” Google’s Westover said, in identical language to what Google gave out after Duo’s report.
MANCHESTER: Manchester United's Champions League qualification hopes suffered a blow after an equaliser deep in stoppage time from Michael Obafemi earned Southampton a 2-2 draw in the Premier League at Old Trafford on Monday. United, unbeaten in 18 games in all competitions, were poised to m Read More...
KATHMANDU, JULY 13 With just two days remaining for the 2019-20 fiscal year to end, capital budget expenditure throughout the year stands at one of the worst ever at 39.62 per cent. Officials at the Ministry of Finance said capital expenditure during the current fiscal year, which was primaril Read More...
Kathmandu, July 13 Mayur Yatayat Company resumed its bus services from today in Kathmandu valley amid the COVID-19 pandemic. The decision of Mayur Yatayat has come as a relief to commuters at a time when other public transportation entrepreneurs were refusing to operate their services citing f Read More...
Kathmandu, July 13 Minister of Communications and Information Technology Dr Yubaraj Khatiwada said the CIT Ministry ought to start digitisation first, by utilising the advancement of information technology. As the government has adopted a digital framework, we should become paperless in our activ Read More...
Kathmandu, July 13 Police have nabbed one of the two prime murder suspects of the much-hyped Sitapaila murder case that had happened 13 years ago. Two workers at a saw mill had allegedly killed its owner, his wife and inflicted serious injuries to their 15-year-old son on the night of 2 Januar Read More...
MIAMI: The resurgence of the coronavirus in the United States ignited fierce debate Monday about whether to reopen schools, as global health officials warned that the pandemic will intensify unless more countries adopt comprehensive plans to combat it. “If the basics aren’t followed, there is Read More...
Kathmandu, July 13 Tokha Municipality in Kathmandu has set priorities for containment of COVID-19 crisis and disaster management in the budget for the upcoming fiscal year. The municipality that is located in the northern belt of Kathmandu unveiled a budget for Rs 1.58 billion for the fiscal y Read More...
WASHINGTON: The federal government incurred the biggest monthly budget deficit in history in June as spending on programs to combat the coronavirus recession exploded while millions of job losses cut into tax revenues. The Treasury Department reported Monday that the deficit hit $864 billion last Read More...