Millions of Chrome, Edge Users Affected by Hijacked Browser Extensions

Contact Your Elected Officials

Malicious extensions masqueraded as popular tools, secretly tracking browsing habits and exposing millions to hijacking risks, researchers warn.

More than 2 million users of Google Chrome and Microsoft Edge have fallen victim to what cybersecurity researchers at Koi Security call a โ€œsophisticatedโ€ malware campaignโ€”one of the largest browser hijacking operations the cybersecurity company has ever uncovered.

The campaignโ€”dubbed RedDirectionโ€”centered on a set of 18 malicious browser extensions that available for download from both Googleโ€™s Chrome Web Store and Microsoftโ€™s Edge Add-ons, according to a July 8 Koi Security report. All of the identified extensions, which are listed at the bottom of this article along with their ID numbers, have since been removed from both platforms.

The malicious extensions appeared legitimate, offering tools such as VPN proxies for TikTok and Discord, YouTube unblockers, weather forecasts, video speed controllers, and emoji keyboards. However, behind the scenes, they secretly enabled covert tracking of usersโ€™ browsing activity, collected URLs of visited pages, and exfiltrated unique tracking identifiers, according to Koi Securityโ€™s findings.

โ€œThese arenโ€™t theoretical attacks,โ€ wrote Koi Securityโ€™s Idan Dardikman. โ€œWith 2.3 million users under surveillance across eighteen different extensions, the campaign creates a massive persistent man-in-the-middle capability that can be exploited at any moment. Every click, every website visit, every online transaction becomes a potential attack vector across this vast network.โ€

The malware implements what Dardikman said was a โ€œsophisticated browser hijacking mechanismโ€ that becomes active every time a user navigates to a new website. It can capture the website address and send it to a remote serverโ€”along with the userโ€™s unique tracking ID number. Hackers can also configure the malware to automatically redirect users to different websites, which are potentially harmful.

While Koi Security has not publicly attributed the operation to a specific threat actor or nation-state, the researchers described RedDirection as a highly organized and  โ€œparticularly deviousโ€ effort that amounted to one of the largest browser hijacking operations the company has ever documented. Many of the extensions initially functioned exactly as advertised, which helped them build positive user ratings and evade suspicion on official browser stores.

โ€œImagine logging into your bankโ€™s website,โ€ Dardikman wrote in the report. โ€œThe extension captures your request and seamlessly redirects you to a pixel-perfect replica of your bankโ€™s login page, hosted on the attackerโ€™s servers. You enter your credentials, thinking youโ€™re securely accessing your account, but youโ€™ve just handed over your banking information to cybercriminals.โ€

Koi Security recommended that users who have installed one of the 18 RedDirection campaign extensions remove it immediately, and then clear their browsing data to remove any tracking identifiers that may be stored on their computers. The company also urged users to run a full system malware scan to check for other infections, and recommended that people monitor their accounts for any suspicious activity.

A review of both Googleโ€™s Chrome Web Store and Microsoftโ€™s Edge Add-ons marketplace indicated that the 18 extensions are no longer available for download.

The Epoch Times has reached out to Google and Microsoft for comment.

A list of the known malicious extensions linked to RedDirection, along with their unique extension IDs, is provided below for reference:

Chrome Extensions:

  • Emoji keyboard onlineโ€”copy & paste your emoji (ID: kgmeffmlnkfnjpgmdndccklfigfhajen)
  • Free Weather Forecast (ID: dpdibkjjgbaadnnjhkmmnenkmbnhpobj)
  • Video Speed Controllerโ€”Video manager (ID: gaiceihehajjahakcglkhmdbbdclbnlf)
  • Unlock Discordโ€”VPN Proxy to Unblock Discord Anywhere (ID: mlgbkfnjdmaoldgagamcnommbbnhfnhf)
  • Dark Themeโ€”Dark Reader for Chrome (ID: eckokfcjbjbgjifpcbdmengnabecdakp)
  • Volume Maxโ€”Ultimate Sound Booster (ID: mgbhdehiapbjamfgekfpebmhmnmcmemg)
  • Unblock TikTokโ€”Seamless Access with One-Click Proxy (ID: cbajickflblmpjodnjoldpiicfmecmif)
  • Unlock YouTube VPN (ID: pdbfcnhlobhoahcamoefbfodpmklgmjm)
  • Color Picker, Eyedropperโ€”Geco colorpick (ID: eokjikchkppnkdipbiggnmlkahcdkikp)
  • Weather (ID: ihbiedpeaicgipncdnnkikeehnjiddck)

Edge Extensions:

  • Unlock TikTok (ID: jjdajogomggcjifnjgkpghcijgkbcjdi)
  • Volume Boosterโ€”Increase your sound (ID: mmcnmppeeghenglmidpmjkaiamcacmgm)
  • Web Sound Equalizer (ID: ojdkklpgpacpicaobnhankbalkkgaafp)
  • Header Value (ID: lodeighbngipjjedfelnboplhgediclp)
  • Flash Playerโ€”games emulator (ID: hkjagicdaogfgdifaklcgajmgefjllmd)
  • Youtube Unblocked (ID: gflkbgebojohihfnnplhbdakoipdbpdm)
  • SearchGPTโ€”ChatGPT for Search Engine (ID: kpilmncnoafddjpnbhepaiilgkdcieaf)
  • Unlock Discord (ID: caibdnkmpnjhjdfnomfhijhmebigcelo)

By Tom Ozimek

Read on TheepochTimes.com

The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Whatโ€™s The Real Reason Why The Economist Wants Europe To Spend $400 Billion More On Ukraine?

The Economist urges Europeโ€™s elites to fund Ukraineโ€™s $390B recovery, arguing itโ€™s cheaper than facing the costs of inaction over the next four years.

Fourth and funded: The business of buyouts

Through week ten of the college football season, the ledger on what universities owe their former coaches in buyouts was nearly $185 million.ย 

Deflating Portland: Why Antifa Went from Black Blok to Inflatable Costumes

Antifa's transformation from militant to mascot is so absurd it's almost comedic. Yet beneath the humor lies something calculated. Itโ€™s all about optics.

The Affordable Care Act: The Great Deception of โ€œAffordableโ€

When the Affordable Care Act was introduced, people trusted what they were told. The truth is, the ACA has done the exact opposite of what it claimed.

Trumpโ€™s Tariffs Lead to Jeep Coming Home

Thanks to Trump, Stellantis will produce the Compass and Cherokee vehicles in Belvidere, IL and this decision had nothing to do with Biden or Pritzker.

Children Face Higher Risk of Neurodevelopmental Disorders If Exposed to COVID-19 in Womb: Study

Children whose mothers contracted COVID-19 while pregnant face an elevated risk of neurodevelopmental disorder, according to a new paper.

Trump Says SNAP Benefits Wonโ€™t Be Paid Until Government Reopens

USDA says states must recode systems to reflect reduced SNAP benefits, a process that could take anywhere from a few weeks to several months.

Charles Murray Reflects on Faith, Science, and Americaโ€™s Cultural Divide

Charles Murray's spiritual awakening reshaped his views on science and society, warning the Westโ€™s loss of faith has created a dangerous cultural void.

New York Urges Court to Dismiss Challenge of Content Moderation Rules

X lawsuit argues that New York state content moderation rules would compel disclosure of โ€˜controversial speechโ€™ protected by the First Amendment.

Trump Re-Nominates Jared Isaacman for NASA Administrator

Trailblazing civilian astronaut Jared Isaacman is once again President Donald Trumpโ€™s choice for NASAโ€™s administrator.

US Agencies Terminate 103 Wasteful Contracts With $4.4 Billion Ceiling Value: DOGE

Government agencies canceled 103 wasteful contracts worth $4.4 billion, saving $103 million in five days, according to the Department of Government Efficiency.

Food Stamp Payments Could Restart by Wednesday as Ordered by Judge: Bessent

The Trump administration awaits court decisions on funding food stamp benefits for low-income Americans amid the ongoing government shutdown.

Trump Threatens Nigeria With US Military Action If It Doesnโ€™t Confront Killings of Christians

President Trump on Nov. 1 threatened military action in Nigeria if the West African country doesnโ€™t do more to halt the killing of Christians.
spot_img

Related Articles