#1 Middle East & Africa Trusted Cybersecurity News & Magazine |

39 C
Dubai
Thursday, July 31, 2025
HomeTopics 1Browser & CybersecurityRogue Chrome and Edge Extensions Infect Over 300,000 Users with Malware

Rogue Chrome and Edge Extensions Infect Over 300,000 Users with Malware

Date:

Related stories

Allianz Life Suffers Data Breach via External Hack: Consumer Data at Risk

Allianz Life Insurance Company of North America has disclosed...

US Nuclear Agency Hacked Through Microsoft SharePoint Flaws

Microsoft SharePoint has frequently made headlines—and often for negative...
spot_imgspot_imgspot_imgspot_img

A newly discovered malicious campaign has infected over 300,000 users with malware disguised as Chrome and Edge extensions. The campaign, orchestrated by a sophisticated cybercrime group, leverages deceptive tactics to trick users into installing malicious software, granting attackers access to sensitive data and system control.

The Stealthy Threat

The malicious extensions, posing as legitimate productivity or utility tools, have been distributed through various channels, including third-party app stores and social media platforms. Once installed, these extensions silently infiltrate the user’s system, granting attackers remote access and enabling them to steal personal information, financial data, and browsing history.

Furthermore, the malware can be used to deploy additional payloads, such as ransomware or cryptocurrency miners, causing further damage to the infected system. The cybercriminals behind this campaign have demonstrated a high level of sophistication, employing techniques to evade detection by antivirus software and security measures.

Impact on Users and Organizations

The infection of over 300,000 users highlights the significant scale of this malicious campaign. The stolen data can be used for identity theft, financial fraud, and other malicious purposes. Organizations may also be at risk if employees are infected, as compromised devices can serve as entry points for broader network attacks.

Protecting Yourself from Malicious Extensions

To safeguard against malware disguised as Chrome and Edge extensions, follow these essential steps:

  1. App Vetting: Download extensions only from official app stores like the Chrome Web Store or Microsoft Edge Add-ons.
  2. Permission Management: Carefully review the permissions requested by extensions and grant only necessary access.
  3. Regular Updates: Keep your browser and operating system up-to-date with the latest security patches.
  4. Strong Passwords: Use strong, unique passwords for all online accounts.
  5. Two-Factor Authentication: Enable two-factor authentication whenever possible.
  6. Beware of Phishing: Be cautious of suspicious emails, text messages, and links that could lead to malicious websites.
  7. Antivirus Protection: Install a reputable antivirus app on your device.
  8. Regular Backups: Create regular backups of your important data.
  9. Security Awareness Training: Educate yourself and family members about cyber threats.
  10. Limit Extension Usage: Only install necessary extensions and remove those that are no longer used.

Conclusion

The malicious extension campaign targeting Chrome and Edge users underscores the importance of exercising caution when installing browser extensions. Cybercriminals continue to develop new tactics to exploit user trust and compromise systems. By following these security best practices, individuals and organizations can significantly reduce their risk of falling victim to such attacks.

Want to stay on top of cybersecurity news? Follow us on Facebook – X (Twitter) – Instagram – LinkedIn – for the latest threats, insights, and updates!

Ouaissou DEMBELE
Ouaissou DEMBELEhttp://cybercory.com
Ouaissou DEMBELE is a seasoned cybersecurity expert with over 12 years of experience, specializing in purple teaming, governance, risk management, and compliance (GRC). He currently serves as Co-founder & Group CEO of Sainttly Group, a UAE-based conglomerate comprising Saintynet Cybersecurity, Cybercory.com, and CISO Paradise. At Saintynet, where he also acts as General Manager, Ouaissou leads the company’s cybersecurity vision—developing long-term strategies, ensuring regulatory compliance, and guiding clients in identifying and mitigating evolving threats. As CEO, his mission is to empower organizations with resilient, future-ready cybersecurity frameworks while driving innovation, trust, and strategic value across Sainttly Group’s divisions. Before founding Saintynet, Ouaissou held various consulting roles across the MEA region, collaborating with global organizations on security architecture, operations, and compliance programs. He is also an experienced speaker and trainer, frequently sharing his insights at industry conferences and professional events. Ouaissou holds and teaches multiple certifications, including CCNP Security, CEH, CISSP, CISM, CCSP, Security+, ITILv4, PMP, and ISO 27001, in addition to a Master’s Diploma in Network Security (2013). Through his deep expertise and leadership, Ouaissou plays a pivotal role at Cybercory.com as Editor-in-Chief, and remains a trusted advisor to organizations seeking to elevate their cybersecurity posture and resilience in an increasingly complex threat landscape.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img

LEAVE A REPLY

Please enter your comment!
Please enter your name here