Clear, practical technology insights BSOD Code Lookup · Windows Error Code Lookup · Wi-Fi Troubleshooting · PC Troubleshooting Checklist

Hacker Uses Browser Extension to Take Over Target's Gmail Account

Learn about Malicious Extension, including Friarfox. Malicious Extension, key uses, practical steps, common issues, and answers to frequently asked questions.

Table of Contents

This guide provides a clear overview of malicious extension, including Friarfox. Malicious Extension. Use it to understand the topic, compare the available options, and make a more informed decision.

Initial investigation showed that this attack campaign was conducted by a hacker group with relatively close ties to China - TA413. Coordination activities began in January and continued throughout February, according to a Proofpoint report published on February 25.

Notably, this malicious campaign featured Scanbox, a malicious code known for its ability to spy on information. Scanbox can allow malicious actors to accurately collect data of the target, and also record their keystrokes.

"Scanbox has been used in multiple campaigns since 2014 to target the Tibetan immigrant community along with other ethnic minorities in China," the Proofpoint experts said. "This malware is also capable of tracking visitor data to specific websites, performing logging and collecting user data that can be leveraged in future intrusion attempts.".

Malicious Extension guide image 1

Friarfox. Malicious Extension

As detected by Proofpoint, phishing emails sent by attackers (TA413) to the target's mailboxes redirect them to a 'you-tube[.]tv' domain controlled by themselves. The domain is then displayed disguised as a fake Adobe Flash Player Update landing page.

JavaScript configuration scripts executed from this domain will automatically prompt targets to install a malicious add-on called FriarFox if they are using the Firefox web browser and signed in to their Gmail account.

If the target uses any other web browser (not Firefox), they will be redirected to the legitimate YouTube login page. If they're using Firefox but aren't signed in to their Gmail account, they'll be asked to add this malicious FriarFox add-on to their browser.

FriarFox was developed on top of the legitimate open source Firefox Notifier extension, by changing its icon and description metadata to mimic the Flash update process. In addition, FriarFox also attached (in an intentional manner) malicious JavaScripts designed to take over the victim's Gmail account and infect their system with Scanbox malware.

When a victim is tricked into installing the FriarFox extension, the TA413 malicious actors take over the victim's Gmail account and use the victim's Firefox browser to perform the following malicious actions:

For Gmail accounts:

  • Search email
  • Email archiving
  • Get Gmail notifications
  • Read emails
  • Change Firefox browser's visual and audio alert features for FriarFox extension
  • Label your email
  • Mark email as spam
  • Delete message
  • Refresh inbox
  • Email forwarding
  • Delete messages from Gmail trash
  • Send email from compromised account

For Firefox (based on browser permissions):

  • Access user data for all sites.
  • show notification
  • Read and modify privacy settings
  • Access browser tabs.

'The use of browser extensions to target users' private Gmail accounts combined with Scanbox malware distribution demonstrates TA413's experience and skill,' Proofpoint concluded. essay.

Conclusion

Understanding Malicious Extension makes it easier to compare options, avoid common mistakes, and apply the information in this guide more effectively. Review the relevant requirements before making changes or choosing a solution.

FAQ

What is Malicious Extension?

"This malware is also capable of tracking visitor data to specific websites, performing logging and collecting user data that can be leveraged in future intrusion attempts.".

Why is Malicious Extension important?

Understanding Malicious Extension helps you evaluate features, compatibility, performance, and potential limitations before you choose a product or follow a procedure.

What should you consider when using or choosing Malicious Extension?

Consider your specific goal, compatibility requirements, available features, cost, security, and the practical recommendations described in this guide.

Discussion

Reader Comments 0

Sign in with email or Google to join the discussion.