Browser Extensions

T1176.001

Sub-technique of T1176 Software Extensions.View on attack.mitre.org

About this technique

Adversaries may abuse internet browser extensions to establish persistent access to victim systems. Browser extensions or plugins are small programs that can add functionality to and customize aspects of internet browsers. They can be installed directly via a local file or custom URL or through a browser's app store - an official online platform where users can browse, install, and manage extensions for a specific web browser. Extensions generally inherit the web browser's permissions previously granted.

Malicious extensions can be installed into a browser through malicious app store downloads masquerading as legitimate extensions, through social engineering, or by an adversary that has already compromised a system. Security can be limited on browser app stores, so it may not be difficult for malicious extensions to defeat automated scanners. Depending on the browser, adversaries may also manipulate an extension's update url to install updates from an adversary-controlled server or manipulate the mobile configuration file to silently install additional extensions.

Adversaries may abuse how chromium-based browsers load extensions by modifying or replacing the Preferences and/or Secure Preferences files to silently install malicious extensions. When the browser is not running, adversaries can alter these files, ensuring the extension is loaded, granted desired permissions, and will persist in browser sessions. This method does not require user consent and extensions are silently loaded in the background from disk or from the browser's trusted store.

Previous to macOS 11, adversaries could silently install browser extensions via the command line using the profiles tool to install malicious .mobileconfig files. In macOS 11+, the use of the profiles tool can no longer install configuration profiles; however, .mobileconfig files can be planted and installed with user interaction.

Once the extension is installed, it can browse to websites in the background, steal all information that a user enters into a browser (including credentials), and be used as an installer for a RAT for persistence.

There have also been instances of botnets using a persistent backdoor through malicious Chrome extensions for Command and Control. Adversaries may also use browser extensions to modify browser permissions and components, privacy settings, and other security controls for Stealth.

Detection rules3

Rules on DetectionCode tagged with T1176.001.

Sigma2

RuleLevelLog source
Suspicious Chromium Browser Instance Executed With Custom Extensionhighwindows / process_creation
Chromium Browser Instance Executed With Custom Extensionmediumwindows / process_creation

Splunk1

RuleTypeRiskData source
Windows Disable Internet Explorer AddonsAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups1

Software6

Campaigns0

None recorded.

Procedure examples7

Groups1

Used byProcedure example
GroupKimsuky

Kimsuky has used Google Chrome browser extensions to infect victims and to steal passwords and cookies.

Software6

Used byProcedure example
MalwareBundlore

Bundlore can install malicious browser extensions that are used to hijack user searches.

MalwareGrandoreiro

Grandoreiro can use malicious browser extensions to steal cookies and other user information.

MalwareLumma Stealer

Lumma Stealer has installed a malicious browser extension to target Google Chrome, Microsoft Edge, Opera and Brave browsers for the purpose of stealing data.

MalwareMispadu

Mispadu utilizes malicious Google Chrome browser extensions to steal financial data.

MalwareOSX/Shlayer

OSX/Shlayer can install malicious Safari browser extensions to serve ads.

MalwareTRANSLATEXT

TRANSLATEXT has the ability to capture credentials, cookies, browser screenshots, etc. and to exfiltrate data.

References13

  1. Banker Google Chrome Extension Steals Creds Open source
    Marinho, R. (n.d.). (Banker(GoogleChromeExtension)).targeting. Retrieved November 18, 2017.
  2. Browers FriarFox Open source
    Raggi, Michael. Proofpoint Threat Research Team. (2021, February 25). TA413 Leverages New FriarFox Browser Extension to Target the Gmail Accounts of Global Tibetan Organizations. Retrieved November 17, 2024.
  3. Browser Adrozek Open source
    Microsoft Threat Intelligence. (2020, December 10). Widespread malware campaign seeks to silently inject ads into search results, affects multiple browsers. Retrieved February 26, 2024.
  4. Catch All Chrome Extension Open source
    Marinho, R. (n.d.). "Catch-All" Google Chrome Malicious Extension Steals All Posted Data. Retrieved November 16, 2017.
  5. Chrome Extension C2 Malware Open source
    Kjaer, M. (2016, July 18). Malware in the browser: how you might get hacked by a Chrome extension. Retrieved September 12, 2024.
  6. Chrome Extension Crypto Miner Open source
    Brinkmann, M. (2017, September 19). First Chrome extension with JavaScript Crypto Miner detected. Retrieved November 16, 2017.
  7. Chrome Extensions Definition Open source
    Chrome. (n.d.). What are Extensions?. Retrieved November 16, 2017.
  8. ICEBRG Chrome Extensions Open source
    De Tore, M., Warner, J. (2018, January 15). MALICIOUS CHROME EXTENSIONS ENABLE CRIMINALS TO IMPACT OVER HALF A MILLION USERS AND GLOBAL BUSINESSES. Retrieved January 17, 2018.
  9. Malicious Chrome Extension Numbers Open source
    Jagpal, N., et al. (2015, August). Trends and Lessons from Three Years Fighting Malicious Extensions. Retrieved November 17, 2017.
  10. Pulsedive Open source
    Pulsedive Threat Research. (2025, March 21). Rilide - An Information Stealing Browser Extension. Retrieved September 22, 2025.
  11. Stantinko Botnet Open source
    Vachon, F., Faou, M. (2017, July 20). Stantinko: A massive adware campaign operating covertly since 2012. Retrieved November 16, 2017.
  12. Wikipedia Browser Extension Open source
    Wikipedia. (2017, October 8). Browser Extension. Retrieved January 11, 2018.
  13. xorrior chrome extensions macOS Open source
    Chris Ross. (2019, February 8). No Place Like Chrome. Retrieved April 27, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.