Malicious Chrome and Edge add-ons: how to spot them and why they’re dangerous | Kaspersky official blog

Refract AI Intelligence Digest

BLUF

Rogue browser extensions compromise user security by stealing credentials and funds from within the trusted browser environment.

NEWS

Kaspersky researchers warn of malicious Chrome and Edge add-ons that exfiltrate passwords, drain crypto wallets, and display deceptive ClickFix instructions. These threats operate by tricking users into installing extensions that request excessive permissions under the guise of legitimate tools.

Why I Care

This campaign impacts all browser users but poses severe financial risk to cryptocurrency holders and credential theft for general users, bypassing standard antivirus protections.

Next Steps

End users and IT teams should audit all installed browser extensions immediately today. Remove any unfamiliar add-ons, reset browser permissions, and report suspicious behavior to security vendors.

How malicious Chrome extensions steal passwords, drain cryptocurrency wallets and display fake ClickFix instructions, and what to do if you find one of these extensions installed in your browser.
Back to Blog Listing

Source: Kaspersky Security Blog ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.