Browse Definitions :
Definition

browser extension malware

Extension malware is any browser extension that was developed intentionally with coding that causes undesirable behaviors or whose code has been compromised by an attacker to do so.

Like other types of software, browser extensions can be designed to carry out attacks. In January 2018, for example, a security company called ICEBERG reported that they had detected four malicious extensions available from the Chrome Web Store. The four -- Change HTTP Request Header, Nyoogle - Custom Logo for Google, Lite Bookmarks and Stickies - Chrome's Post-it Notes -- were apparently designed to conduct click fraud and black hat SEO practices. ICEBERG warned that the same access methods that enabled those behaviors could also make it possible for the attackers to breach corporate networks and gather sensitive data.

Although Google subsequently removed the four extensions from the store, ICEBERG noted that the extensions may still exist on the machines of people who downloaded them and that they may also still be available through third-party repositories.

In other cases, an extension may be hijacked by an attacker. According to threat protection vendor Proofpoint, in July and August of 2017, eight compromised Chrome browser extensions (Copyfish, Web Developer, Chrometana, Infinity New Tab, Web Paint, Social Fixer, TouchVPN and Betternet VPN ) sent malicious code to nearly 4.8 million users. Targeted users were shown a JavaScript alert that said their PC needed to be repaired and were then directed to pay for the false repairs, enabling the attackers to profit from this scheme.

Security experts recommend that users be judicious when installing browser extensions. Whenever possible, you should check what permissions an extension requires. It’s wise, as well, to refrain from installing extensions from unknown companies and developers.

This was last updated in January 2018

Continue Reading About browser extension malware

SearchCompliance

  • information governance

    Information governance is a holistic approach to managing corporate information by implementing processes, roles, controls and ...

  • enterprise document management (EDM)

    Enterprise document management (EDM) is a strategy for overseeing an organization's paper and electronic documents so they can be...

  • risk assessment

    Risk assessment is the identification of hazards that could negatively impact an organization's ability to conduct business.

SearchSecurity

  • honeypot (computing)

    A honeypot is a network-attached system set up as a decoy to lure cyber attackers and detect, deflect and study hacking attempts ...

  • spam trap

    A spam trap is an email address that is used to identify and monitor spam email.

  • cracker

    A cracker is someone who breaks into someone else's computer system, often on a network; bypasses passwords or licenses in ...

SearchHealthIT

SearchDisasterRecovery

  • risk mitigation

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a business.

  • call tree

    A call tree is a layered hierarchical communication model that is used to notify specific individuals of an event and coordinate ...

  • Disaster Recovery as a Service (DRaaS)

    Disaster recovery as a service (DRaaS) is the replication and hosting of physical or virtual servers by a third party to provide ...

SearchStorage

  • cloud testing

    Cloud testing is the process of using the cloud computing resources of a third-party service provider to test software ...

  • storage virtualization

    Storage virtualization is the pooling of physical storage from multiple storage devices into what appears to be a single storage ...

  • erasure coding

    Erasure coding (EC) is a method of data protection in which data is broken into fragments, expanded and encoded with redundant ...

Close