• Login
Whats Current In
No Result
View All Result
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development
No Result
View All Result
Whats Current In
No Result
View All Result
Home Cyber Security

Facebook accounts hijacked by new malicious ChatGPT Chrome extension

Bill Toulas by Bill Toulas
March 22, 2023
Reading Time: 3 mins read
0
New WhiskerSpy malware delivered via trojanized codec installer

Hacker

RELATED POSTS

CISA warns govt agencies of recently patched Barracuda zero-day

QBot malware abuses Windows WordPad EXE to infect devices

Hot Pixels attack checks CPU temp, power changes to steal data

A trojanized version of the legitimate ChatGPT extension for Chrome is gaining popularity on the Chrome Web Store, accumulating over 9,000 downloads while stealing Facebook accounts.

The extension is a copy of the legitimate popular add-on for Chrome named “ChatGPT for Google” that offers ChatGPT integration on search results. However, this malicious version includes additional code that attempts to steal Facebook session cookies.

The publisher of the extension uploaded it to the Chrome Web Store on February 14, 2023, but only started promoting it using Google Search advertisements on March 14, 2023. Since then, it has had an average of a thousand installations per day.

Add-on available on Chrome Web Store
Add-on available on the Chrome Web Store (BleepingComputer)

The researcher who discovered it, Nati Tal of Guardio Labs, reports that the extension is communicating with the same infrastructure used earlier this month by a similar Chrome add-on that amassed 4,000 installations before Google removed it from the Chrome Web Store.

Hence, this new variant is considered part of the same campaign, which the operators kept as a backup on the Chrome Web Store for when the first extension would be reported and removed.

Targeting Facebook accounts

The malicious extension is promoted via advertisements in Google Search results, which are prominently featured when searching for “Chat GPT 4.”

Buy JNews
ADVERTISEMENT

Clicking on the sponsored search results takes users to a fake “ChatGPT for Google” landing page, and from there, to the extension’s page on Chrome’s official add-on store.

After the victim installs the extension, they get the promised functionality (ChatGPT integration on search results) since the legitimate extension’s code is still present. However, the malicious add-on also attempts to steal session cookies for Facebook accounts.

Infection chain
Infection chain (Guardio Labs)

Upon the extension’s installation, malicious code uses the OnInstalled handler function to steal Facebook session cookies.

These stolen cookies allow the threat actors to log in to a Facebook account as the user and gain full access to their profiles, including any business advertising features.

The malware abuses the Chrome Extension API to acquire a list of Facebook-related cookies and encrypts them using an AES key. It then exfiltrates the stolen data via a GET request to the attacker’s server.

Retrieving list of cookies from Google Chrome
Retrieving list of cookies from Google Chrome (Guardio Labs)

“The cookies list is encrypted with AES and attached to the X-Cached-Key HTTP header value,” explains the Guardio Labs report.

“This technique is used here to try and sneak the cookies out without any DPI (Deep Packet Inspection) mechanisms raising alerts on the packet payload.”

The threat actors then decrypt the stolen cookies to hijack their victims’ Facebook sessions for malvertizing campaigns or to promote banned material like ISIS propaganda.

Facebook page of an RV seller taken over by the attacker
Facebook page of an RV seller taken over by the attacker (Guardio Labs)

The malware automatically changes the login details on the breached accounts to prevent the victims from regaining control over their Facebook accounts. It also switches the profile name and picture to a fake persona named “Lilly Collins.”

At this time, the malicious Google Chrome extension is still present in the Google Chrome Web Store.

However, the security researcher reported the malicious extension to the Chrome Web Store team, which will likely be removed soon. 

Unfortunately, based on previous history, the threat actors likely have a plan ‘C’ via another “parked” extension that could facilitate the next infection wave.

BleepingComputer contacted Google with further questions about the extension, but a response was not immediately available.

Share54Tweet34Pin12
Bill Toulas

Bill Toulas

Related Posts

CISA orders govt agencies to update iPhones, Macs by May 1st
Cyber Security

CISA warns govt agencies of recently patched Barracuda zero-day

May 27, 2023
New QakNote attacks push QBot malware via Microsoft OneNote files
Cyber Security

QBot malware abuses Windows WordPad EXE to infect devices

May 27, 2023
Hot Pixels attack checks CPU temp, power changes to steal data
Cyber Security

Hot Pixels attack checks CPU temp, power changes to steal data

May 27, 2023
Time to challenge yourself in the 2023 Google CTF!
Cyber Security

Time to challenge yourself in the 2023 Google CTF!

May 26, 2023
Time to challenge yourself in the 2023 Google CTF!
Cyber Security

Time to challenge yourself in the 2023 Google CTF!

May 26, 2023
The Week in Ransomware – December 16th 2022 – Losing Trust
Cyber Security

The Week in Ransomware – May 26th 2023 – Cities Under Attack

May 26, 2023

Recommended Stories

Windows zero-day vulnerability exploited in ransomware attacks

Fake in-browser Windows updates push Aurora info-stealer malware

May 10, 2023
Morpher launches unique market for virtual collectibles

Morpher launches unique market for virtual collectibles

May 8, 2023
Tron reports another week of positive growth- Here are its latest milestones

Tron reports another week of positive growth- Here are its latest milestones

March 23, 2023

Popular Stories

  • New Python malware backdoors VMware ESXi servers for remote access

    Massive ESXiArgs ransomware attack targets VMware ESXi servers worldwide

    137 shares
    Share 55 Tweet 34
  • Facts and myths about the warriors who raided Europe and explored the New World

    137 shares
    Share 55 Tweet 34
  • Exploit released for actively abused ProxyNotShell Exchange bug

    137 shares
    Share 55 Tweet 34
  • New Windows Server updates cause domain controller freezes, restarts

    136 shares
    Share 54 Tweet 34
  • Bing Chat’s secret modes turn it into a personal assistant or friend

    136 shares
    Share 54 Tweet 34
Whats Current In

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Visit our landing page to see all features & demos.

LEARN MORE »

Recent Posts

  • XRP settlement: A turning point in US crypto regulations?
  • Uniswap spikes despite StarkNet; Avalanche in pursuit?
  • Avorak AI: A leading force in the crypto space

Categories

  • Apple Computer
  • Blockchain
  • Cyber Security
  • Tech News
  • Venture Capital

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?