Blog

Natalie Zargarov Published - December 24, 2025

Silent Takeover: How Purchased Chrome Extensions Became Remote-Controlled Webpage Manipulation Tools

  Executive Summary Our investigation uncovered a coordinated campaign in which multiple Chrome extensions—initially benign and serving unrelated purposes—were transformed into remotely controlled content-injection tools. Although the extensions appeared harmless and requested no special permissions, each was modified to periodically download a configuration file from an attacker-controlled domain. These dynamic rules allowed the extensions to […]

Learn More
Silent Takeover: How Purchased Chrome Extensions Became Remote-Controlled Webpage Manipulation Tools