Menu
Current Affairs of This Week
Current Affairs of This Week

Exclusive: Massive spying on users of Google’s Chrome shows new security weakness

Posted on June 21, 2020 by admin

By Joseph Menn
SAN FRANCISCO (Reuters) – A newly discovered spyware effort attacked users through 32 million downloads of extensions to Google’s market-leading Chrome web browser, researchers at Awake Security told Reuters, highlighting the tech industry’s failure to protect browsers as they are used more for email, payroll and other sensitive functions.
“When we are alerted of extensions in the Web Store that violate our policies, we take action and use those incidents as training material to improve our automated and manual analyses,” Google spokesman Scott Westover told Reuters.
Most of the free extensions purported to warn users about questionable websites or convert files from one format to another. Instead, they siphoned off browsing history and data that provided credentials for access to internal business tools.
Based on the number of downloads, it was the most far-reaching malicious Chrome store campaign to date, according to Awake co-founder and chief scientist Gary Golomb.
Google declined to discuss how the latest spyware compared with prior campaigns, the breadth of the damage, or why it did not detect and remove the bad extensions on its own despite past promises to supervise offerings more closely.
It is unclear who was behind the effort to distribute the malware. Awake said the developers supplied fake contact information when they submitted the extensions to Google.
“Anything that gets you into somebody’s browser or email or other sensitive areas would be a target for national espionage as well as organized crime,” said former National Security Agency engineer Ben Johnson, who founded security companies Carbon Black and Obsidian Security.
The extensions were designed to avoid detection by antivirus companies or security software that evaluates the reputations of web domains, Golomb said.
If someone used the browser to surf the web on a home computer, it would connect to a series of websites and transmit information, the researchers found. Anyone using a corporate network, which would include security services, would not transmit the sensitive information or even reach the malicious versions of the websites.
“This shows how attackers can use extremely simple methods to hide, in this case, thousands of malicious domains,” Golomb said.
All of the domains in question, more than 15,000 linked to each other in total, were purchased from a small registrar in Israel, Galcomm, known formally as CommuniGal Communication Ltd.
Awake said Galcomm should have known what was happening.
In an email exchange, Galcomm owner Moshe Fogel told Reuters thpany had done nothing wrong.
“Galcomm is not involved, and not in complicity with any malicious activity whatsoever,” Fogel wrote. “You can say exactly the opposite, we cooperate with law enforcement and security bodies to prevent as much as we can.”
Fogel said there was no record of the inquiries Golomb said he made in April and again in May to the company’s email address for reporting abusive behavior, and he asked for a list of suspect domains. Reuters sent him that list three times without getting a substantive response.
The Internet Corp for Assigned Names and Numbers, which oversees registrars, said it had received few complaints about Galcomm over the years, and none about malware.
While deceptive extensions have been a problem for years, they are getting worse. They initially spewed unwanted advertisements, and now are more likely to install additional malicious programs or track where users are and what they are doing for government or commercial spies.
Malicious developers have been using Google’s Chrome Store as a conduit for a long time. After one in 10 submissions was deemed malicious, Google said in 2018 https://blog.chromium.org/2018/10/trustworthy-chrome-extensions-by-default.html it would improve security, in part by increasing human review.
But in February, independent researcher Jamila Kaya and Cisco Systems’ Duo Security uncovered https://duo.com/labs/research/crxcavator-malvertising-2020 a similar Chrome campaign that stole data from about 1.7 million users. Google joined the investigation and found 500 fraudulent extensions.
“We do regular sweeps to find extensions using similar techniques, code and behaviors,” Google’s Westover said, in identical language to what Google gave out after Duo’s report.
(Reporting by Joseph Menn; Editing by Greg Mitchell and Leslie Adler)
obd2 scanner

Top 7 car Diagnostic Scanner

Best Professional OBD2 Scanner
Autel maxisys ultra scanner
Autel MK908p Diagnostic Scanner
Launch scan tool: X431 V+
Autel MaxiDiag MD806 Automotive Car Diagnostic Scanner
launch car code reader: CRP129x
Autel TPMS Tool ts601

Random Posts

  • Singapore moves racist children’s book to library parents’ section after review
  • Aluminum Alloys for Aerospace Market: Industry Size, Share, Trends, Key Players and Forecast 2020-2026 | Alcoa, Rio …
  • Things We Saw Today: Let’s Cook the Egg Sandwich From Birds of Prey
  • Fruit and vegetable prices squashed in October
  • Travis Japan「ViVi」史上初の快挙 抜擢に喜び
  • Brasil estreia nas Eliminatórias da Copa 2022 contra Bolívia no Maracanã

Popular

  • Visa Postpones Rollout Of New Fee Structure - 683 views
  • Whats Driving The Gluten Free Food Market Share? Hero Group Ag, The Hain Celestial Group Inc., Seitz Glutenfrei, Dr … - 525 views
  • 氷川きよし、EXILE MAKIDAIが志村けんさん追悼「真心と御恩は一生忘れません」 - 496 views
  • «Женское обрезание» в Судане признали преступлением - 473 views
  • 爆発的な拡大懸念 新型コロナ 福岡県内で1日最多の17人 自動車工場勤務の男性も 3日まで生産中止 - 465 views

Tags

5G 2021 Analysis Argentina Australia Borussia Dortmund Brazil Bundesliga China Colombia Coronavirus Donald Trump Enterprise European Union Finance Forecasting Germany Government Health Care Industry Japan Juventus F.C. La Liga Law Liverpool F.C. Los Angeles Lakers Manchester United F.C. Manufacturing Market research Market share Mexico NBA NFL Premier League Report Research Russia School Serie A Student System Tennis Turkey UEFA Champions League Vietnam

Recent Posts

  • Navalny has a plan to get out of jail… protests
  • UFC 257: Jessica Eye vs Joanne Calderwood- Prediction and Analysis
  • Vaclík vuelve tras más de un mes y medio lesionado
  • Robert Mardini: «La planète n’a pas le choix: elle doit éliminer les armes nucléaires»
  • Calgary father appeals conviction in drunk driving crash that killed teen daughter
©2021 Current Affairs of This Week | Powered by WordPress & Superb Themes