Google Removes Over 500 Extensions From Chrome Web Store Over Ad Fraud

The malicious extensions were a part of a large network whose activities date back to early 2010s.

Advertisement
By Nadeem Sarwar | Updated: 14 February 2020 16:29 IST
Highlights
  • The malicious Chrome extensions claimed to offer advertising services
  • Malicious actors obfuscated the inherent advertising mechanism
  • Over 1.7 million users were affected by just 70 of these extensions

The fraudulent Chrome extensions involved redirect cycles to generate ad revenue

Google has removed over 500 malicious extensions from the Chrome Web Store over ad fraud. The extensions were found to be a part of a large fraudulent advertising network that injected adware into browsers and pulled browsing data while trapping users with redirect cycles. In some cases, the ads redirected users to websites belonging to big names like Dell and Best Buy, but a majority of them took users to sites that risk malware downloading and phishing. The volume of redirects was also high, which further multiplied the risk posed by these extensions.

The discovery of these shady extensions was made public in a research conducted by independent security researcher Jamila Kaya (@bumblebreaches) and information security expert Jacob Rickerd (@crxpert), and was later published on Cisco-owned Duo. Once the malicious behaviour of these extensions was reported to Google, the company conducted a sweep across the Chrome Web Store and removed more than 500 related extensions.

“We do regular sweeps to find extensions using similar techniques, code, and behaviors, and take down those extensions if they violate our policies”, a Google spokesperson was quoted as saying by Duo.

Advertisement

As per the report, the now-removed Chrome extensions were presented as products that could offer advertising services. But they were found to be a part of a large network comprising of copycat plugins. The research found 70 of these extensions affecting around 1.7 million users, which means the net scale was much larger if there were over 500 such extensions involved in ad fraud.

Advertisement

The malicious Chrome extensions were reportedly created to hide the underlying ad mechanism from users. This made it easier to connect them to a command and control architecture so that browser data can be exfiltrated. During the research, it was found that the extension fraud network has been running for the past couple of years, but their activity potentially dates back to early 2010s. The malicious activity of these Chrome extensions mainly involved ad fraud through a stream of redirects.

Some of the redirects led users to seemingly harmless pages belonging to Dell, Macy's, and Best Buy among others. However, these redirecting streams were mainly used to make users reach a phishing-prone webpage and sites where malware could be downloaded. Bad actors used these extensions to cycle through redirect streams in order to generate ad revenue, and in some cases, these redirects passed well over 30 times.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15 Price in India May Have Leaked via Listing Ahead of Launch
  2. OnePlus 15 Launching Today: Everything You Need to Know
  3. Vivo X300 Series Teased to Launch Soon in India
  4. OnePlus Nord 6 Launch Timeline Revealed in New Leak
  5. Realme Neo 8 Could Launch With 8,000mAh Battery and More
  6. Realme GT 8 Pro Camera Details Confirmed Ahead of Nov 20 India Launch
  7. A Future OnePlus Smartphone Could Debut With a 240Hz Display
  8. iQOO Confirms November Service Day With Complimentary Device Maintenance
  9. Aadhaar vs mAadhaar Key Differences Explained
  10. Best TWS Under Rs 5,000 in India: Realme Buds Air 6 Pro, Sony WF-C510, More
  1. OpenAI Upgrades ChatGPT With GPT-5.1 AI Models, Brings Friendlier Conversations and Less Jargon
  2. iQOO Announces Service Day Benefits Including Free Back Case and Protective Film
  3. Apple Updates Website to Say Apple Intelligence Needs M2 Mac or Newer
  4. iPhone 18 Pro Max Tipped to Be Heavier and Thicker than iPhone 17 Pro Max
  5. OnePlus 16 to Reportedly Come With a 240Hz Dynamic Refresh Rate Screen
  6. OnePlus 15 Launching Today: Know Price in India, Features, Specifications and More
  7. Sangarsha Ghadana - The Art of Warfare OTT Release Date: When and Where to Watch it Online?
  8. Merv To Stream on Prime Video Soon: What You Need to Know Zooey Deschanel and Charlie Cox Heartwarming Rom-Com
  9. Mano Ya Na Mano Now Streaming on YouTube: Know Everything About Cast, Plot, and More
  10. Search for the Truth OTT Release Date: When and Where to Watch it Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.