Amazing Refresh — A Malicious Chrome Extension Running Malware in the Browser
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A security researcher at Report URI uncovered 'Amazing Refresh', a Chrome and Edge browser extension with nearly 100,000 installs that masquerades as a tab auto-refresher while running a sophisticated malware operation. The extension exfiltrates page URLs, user agent data, and element IDs to a C&C server, injects
Table of contents
How we do itBrowser ExtensionsAmazing RefreshScript injectionThe malicious payloadEvasion techniquesImpact on website ownersReporting the malicious extensionsIndicators of CompromiseSort: