Experts Warn of Browser Extensions Spying On Users via Cloud9 Chrome Botnet Network

Share:

The Keksec threat actor has been linked to a previously undocumented malware strain, which has been observed in the wild masquerading as an extension for Chromium-based web browsers to enslave compromised machines into a botnet.

Called Cloud9 by security firm Zimperium, the malicious browser add-on comes with a wide range of features that enables it to siphon cookies, log keystrokes, inject arbitrary JavaScript code, mine crypto, and even enlist the host to carry out DDoS attacks.

The extension “not only steals the information available during the browser session but can also install malware on a user’s device and subsequently assume control of the entire device,” Zimperium researcher Nipun Gupta said in a new report.

The JavaScript botnet isn’t distributed via Chrome Web Store or Microsoft Edge Add-ons, but rather through fake executables and rogue websites disguised as Adobe Flash Player updates.

Once installed, the extension is designed to inject a JavaScript file called “campaign.js” on all pages, meaning the malware could also operate as a standalone piece of code on any website, legitimate or otherwise, potentially leading to watering hole attacks.

The JavaScript code takes responsibility for cryptojacking operations, abusing the victim’s computing resources to illicitly mine cryptocurrencies, as well as inject a second script named “cthulhu.js.”

This attack chain, in turn, exploits flaws in web browsers such as Mozilla Firefox (CVE-2019-11708CVE-2019-9810), Internet Explorer (CVE-2014-6332CVE-2016-0189), and Edge (CVE-2016-7200) to escape the browser sandbox and deploy malware on the system.

The script further acts as a keylogger and a conduit for launching additional commands received from a remote server, allowing it to steal clipboard data, browser cookies, and mount layer 7 DDoS attacks against any domain.

Zimperium attributed the malware to a threat actor tracked as Keksec (aka Kek Security, Necro, and FreakOut), which has a history of developing a wide range of botnet malware, including EnemyBot, for crypto mining and DDoS operations.

The connection to Keksec comes from overlaps in the domains that were previously identified as used by the malware group.

 

The fact that Cloud9 is JavaScript-based and is offered either for free or a small fee on hacker forums makes it possible for less-skilled cybercriminals to get easy access to low-cost options for launching attacks targeting different browsers and operating systems.

The disclosure comes over three months after Zimperium discovered a malicious browser add-on dubbed ABCsoup that posed as a Google Translate tool to strike Russian users of Google Chrome, Opera, and Mozilla Firefox browsers.

“Users should be trained on the risks associated with browser extensions outside of official repositories, and enterprises should consider what security controls they have in place for such risks,” Gupta said.

https://thehackernews.com/2022/11/experts-warn-of-browser-extensions.html

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:26 am, Jul 9, 2025
weather icon 15°C
L: 13° | H: 17°
broken clouds
Humidity: 71 %
Pressure: 1019 mb
Wind: 5 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 59%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:54 am
Sunset: 9:16 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
13° | 17°°C 0.18 mm 18% 7 mph 66 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 29°°C 0 mm 0% 9 mph 73 % 1023 mb 0 mm/h
Fri Jul 11 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 8 mph 64 % 1022 mb 0 mm/h
Sat Jul 12 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 10 mph 66 % 1019 mb 0 mm/h
Sun Jul 13 10:00 pm
weather icon
18° | 31°°C 0 mm 0% 9 mph 69 % 1017 mb 0 mm/h
Today 4:00 am
weather icon
15° | 15°°C 0 mm 0% 3 mph 66 % 1019 mb 0 mm/h
Today 7:00 am
weather icon
17° | 17°°C 0 mm 0% 5 mph 61 % 1020 mb 0 mm/h
Today 10:00 am
weather icon
22° | 22°°C 0 mm 0% 5 mph 57 % 1021 mb 0 mm/h
Today 1:00 pm
weather icon
23° | 23°°C 0 mm 0% 6 mph 55 % 1022 mb 0 mm/h
Today 4:00 pm
weather icon
25° | 25°°C 0.18 mm 18% 7 mph 45 % 1021 mb 0 mm/h
Today 7:00 pm
weather icon
25° | 25°°C 0 mm 0% 7 mph 44 % 1021 mb 0 mm/h
Today 10:00 pm
weather icon
23° | 23°°C 0 mm 0% 3 mph 53 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
20° | 20°°C 0 mm 0% 4 mph 67 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,857.04
0.57%
Ethereum(ETH)
€2,226.27
2.55%
Tether(USDT)
€0.85
0.01%
XRP(XRP)
€1.97
2.00%
Solana(SOL)
€129.27
1.70%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.145430
1.64%
Shiba Inu(SHIB)
€0.000010
1.76%
Pepe(PEPE)
€0.000009
2.41%
Scroll to Top