Google Chrome Spyware Extensions Downloaded 32 Million Times, Let Users Be Spied On: Researchers

Google said it removed more than 70 of the malicious add-ons from its official Chrome Web Store after being alerted by the researchers last month.

Advertisement
By Reuters | Updated: 18 June 2020 13:09 IST
Highlights
  • Google didn't discuss how the latest spyware compared with prior campaign
  • Google said it removed more than 70 add-ons from Chrome Web Store
  • It is unclear who was behind the effort to distribute the malware

The spyware attacked users through 32 million extension downloads on Chrome Web Store

A newly discovered spyware effort attacked users through 32 million downloads of extensions to Google's market-leading Chrome Web browser, researchers at Awake Security told Reuters, highlighting the tech industry's failure to protect browsers as they are used more for email, payroll and other sensitive functions.

Alphabet's Google said it removed more than 70 of the malicious add-ons from its official Chrome Web Store after being alerted by the researchers last month.

“When we are alerted of extensions in the Web Store that violate our policies, we take action and use those incidents as training material to improve our automated and manual analyses,” Google spokesman Scott Westover told Reuters.

Advertisement

Most of the free extensions purported to warn users about questionable websites or convert files from one format to another. Instead, they siphoned off browsing history and data that provided credentials for access to internal business tools.

Based on the number of downloads, it was the most far-reaching malicious Chrome store campaign to date, according to Awake co-founder and chief scientist Gary Golomb.

Google declined to discuss how the latest spyware compared with prior campaigns, the breadth of the damage, or why it did not detect and remove the bad extensions on its own despite past promises to supervise offerings more closely.

Advertisement

It is unclear who was behind the effort to distribute the malware. Awake said the developers supplied fake contact information when they submitted the extensions to Google.

“Anything that gets you into somebody's browser or email or other sensitive areas would be a target for national espionage as well as organized crime,” said former National Security Agency engineer Ben Johnson, who founded security companies Carbon Black and Obsidian Security.

Advertisement

The extensions were designed to avoid detection by antivirus companies or security software that evaluates the reputations of web domains, Golomb said.

If someone used the browser to surf the web on a home computer, it would connect to a series of websites and transmit information, the researchers found. Anyone using a corporate network, which would include security services, would not transmit the sensitive information or even reach the malicious versions of the websites.

Advertisement

“This shows how attackers can use extremely simple methods to hide, in this case, thousands of malicious domains,” Golomb said.

All of the domains in question, more than 15,000 linked to each other in total, were purchased from a small registrar in Israel, Galcomm, known formally as CommuniGal Communication.

Awake said Galcomm should have known what was happening.

In an email exchange, Galcomm owner Moshe Fogel told Reuters that his company had done nothing wrong.

“Galcomm is not involved, and not in complicity with any malicious activity whatsoever,” Fogel wrote. “You can say exactly the opposite, we cooperate with law enforcement and security bodies to prevent as much as we can.”

Fogel said there was no record of the inquiries Golomb said he made in April and again in May to the company's email address for reporting abusive behavior, and he asked for a list of suspect domains. Reuters sent him that list three times without getting a substantive response.

The Internet Corp for Assigned Names and Numbers, which oversees registrars, said it had received few complaints about Galcomm over the years, and none about malware.

While deceptive extensions have been a problem for years, they are getting worse. They initially spewed unwanted advertisements, and now are more likely to install additional malicious programs or track where users are and what they are doing for government or commercial spies.

Malicious developers have been using Google's Chrome Store as a conduit for a long time. After one in 10 submissions was deemed malicious, Google said in 2018 it would improve security, in part by increasing human review.

But in February, independent researcher Jamila Kaya and Cisco Systems' Duo Security uncovered a similar Chrome campaign that stole data from about 1.7 million users. Google joined the investigation and found 500 fraudulent extensions.

“We do regular sweeps to find extensions using similar techniques, code and behaviors,” Google's Westover said, in identical language to what Google gave out after Duo's report.

© Thomson Reuters 2020


Is Mi Notebook 14 series the best affordable laptop range for India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Google, Google Chrome, Spyware
Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo X300 Series Confirmed to Debut With OriginOS 6, Thickness Revealed
  2. Nothing Brings Call Recording to Its Smartphones, But There's a Catch
  3. Oppo Find X9 Series Could Feature These Displays, Cameras
  4. Perseverance Spots Possible Interstellar Comet 3I/ATLAS Over Martian Sky
  5. Apple Releases iOS 26.1 Beta 2 for iPhone With These New Features
  6. RBI-Backed Digital Currency to Be Launched in India, Says Union Minister
  7. HMD Touch 4G Launched in India With 3.2-Inch Display: Price, Features
  8. OnePlus 15T Launch Timeline, Key Features Leaked; Might Bring This Upgrade
  1. NASA’s Juno Probe Faces Silence as Mission Ends Amid Government Shutdown
  2. Perseverance Spots Possible Interstellar Comet 3I/ATLAS Over Martian Sky
  3. Tiny Asteroid 2025 TF Zooms Past Earth Undetected, Closer Than Satellites
  4. A Knight of the Seven Kingdoms OTT Release Revealed: Everything We Know About the Game of Thrones Prequel
  5. RBI to Introduce Pilot for Deposit Tokenisation Using CBDC Layer: Report
  6. Call of Duty: Black Ops 7 Open Beta Extended by a Day Till October 9
  7. MeitY's IndiaAI Mission Taps Five Projects to Drive Safe, Trusted AI in the Country
  8. FIFA World Cup Ticket NFTs Face Swiss Gambling Supervisory Authority’s Scrutiny
  9. Navi UPI Unveils Biometric-Based Payments for iOS, Android at Global Fintech Festival 2025
  10. WhatsApp's Message Translation Feature Is Rolling on iOS With Support for 21 Languages
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.