Site icon TechloMedia

Fake Google Translate Chrome Extension Can Steal Browser Data and Let Hackers Control Chrome Remotely

Chrome logo

A malicious Chrome extension pretending to be Google Translate is giving attackers unusually deep control over infected browsers. Security researchers say the extension can steal browser data, monitor web sessions, and allow attackers to interact with Chrome remotely while keeping much of that activity hidden from the victim.

The campaign was analyzed by VMRay researchers, who found a multi-stage infection chain involving a suspected Rust-based malware loader, an AutoIt script and the Stealc v2 information stealer.

The attack goes beyond the usual browser extension that quietly collects passwords or cookies. The fake extension can also give attackers a live view of Chrome windows and allow them to interact with websites using mouse and keyboard input. That makes the browser itself a tool for the attacker.

Once installed, the extension can collect browser history, bookmarks, information about installed extensions, cookies and stored credentials. This information can provide attackers with access to valuable online accounts or help them identify services worth targeting.

Cookies are particularly valuable because they can sometimes allow attackers to access an already authenticated web session without knowing the account password. Depending on the service and its security protections, stolen browser data could therefore lead to account takeover, access to corporate applications or theft of sensitive information.

The remote-control capability makes the campaign more concerning.

According to the research, attackers can view Chrome windows in real time and interact with websites remotely. The extension can reportedly operate browser windows that are out of focus, meaning the attacker could perform actions in Chrome while the victim is working in another application.

A victim could therefore have an attacker navigating a website, clicking buttons or entering information without immediately seeing what is happening on their screen.

This could be useful for online fraud. An attacker who has already obtained access to a victim’s browser session could potentially use the browser to interact with banking, email, cryptocurrency, cloud or business services.

The extension also has capabilities for configuring a proxy and injecting JavaScript into selected websites. A proxy can allow browser traffic to pass through attacker-controlled infrastructure, while JavaScript injection can change what appears on a legitimate website or alter how the page behaves.

This creates another route for phishing and fraud.

One technique described by researchers involves placing an attacker-controlled page inside an iframe over a legitimate website. The address bar can still show the genuine website’s domain, while the user is actually interacting with a malicious form placed on top of it.

This can make a phishing page much harder to recognize. A victim could see a familiar website address and assume that everything on the page is legitimate before entering a password, authentication code or payment information.

The campaign starts before the malicious extension takes control of Chrome. VMRay found a suspected Rust-based loader that drops the fake extension along with an AutoIt script. The script then deploys Stealc v2, a known information-stealing malware.

This multi-stage approach gives attackers several ways to collect information from the same infected computer. The endpoint malware can target data outside the browser, while the malicious extension focuses on browser sessions and web activity.

The use of a Google Translate name is also deliberate. Translation extensions are common and generally do not look suspicious to users. A malicious add-on that uses a familiar name, icon and description has a better chance of being trusted, particularly if the victim is asked to install it outside the official Chrome Web Store.

This is not the first time attackers have used Google Translate branding to disguise a malicious extension.

In 2024, Zscaler researchers uncovered a Chrome extension called TRANSLATEXT that was uploaded as GoogleTranslate.crx and was linked to the North Korean Kimsuky threat group. That extension could steal credentials, cookies, and browser information and capture screenshots. Zscaler said it was used in a campaign targeting South Korean academics.

The older campaign is important context, but there is no indication from the current research that the newly reported extension is operated by Kimsuky. The similarity is mainly in the use of Google Translate as a trusted disguise.

Chrome extensions can have powerful permissions because they need access to browser tabs, websites, and other browser functions to provide legitimate features. That creates an attractive target for attackers. A user who installs a malicious extension can effectively give malware access to information that would otherwise require a more complicated attack.

Google has also taken steps over the years to reduce the abuse of extensions, including moving developers toward newer extension technologies and tightening permissions. But the basic security problem remains: a browser extension with excessive permissions can see and manipulate a significant amount of what a user does online.

For users, the safest approach is to keep the number of installed extensions small. Remove extensions that you no longer use and check the permissions requested by unfamiliar ones.

Users should also be especially careful with extensions downloaded from websites, GitHub repositories or links shared through messages. If a website asks you to install an extension to view content, fix a browser problem or enable a feature, it is worth checking whether the extension actually comes from the official Chrome Web Store and whether its publisher is trustworthy.

The fake Google Translate campaign also shows why changing a password may not always be enough after a browser compromise. If attackers have already stolen cookies or other session information, they may be able to use an existing authenticated session. Anyone who suspects that a malicious extension has been installed should remove it, scan the system for malware and review active sessions on important accounts.

The researchers have identified several indicators associated with the campaign, including hashes for the suspected Rust loader, fake Google Translate extension, AutoIt script and Stealc v2 payload. The reported command-and-control infrastructure includes 87.120.104[.]147:8080 and 160.20.109[.]33:80.

The exact distribution method for the current campaign is not clear from the available research. That means users should not assume that seeing a Google Translate extension alone means they have been infected.

It highlights that browser extensions deserve the same level of caution as other software installed on a computer. An extension may look like a small browser utility, but with the right permissions it can potentially see and manipulate a large part of a user’s online activity.

And in this case, the risk goes a step further. Attackers are not just trying to steal what is already inside Chrome. They can potentially use the browser itself as a remote interface for carrying out actions against the victim’s accounts.

Exit mobile version