Hackers Leverage Trusted Extensions & Tools to Spread Malware

In the latter half of 2024, threat actors have increasingly turned to trusted browser extensions and built-in Microsoft tools to deliver malware and establish persistence on target systems.

This shift in tactics, highlighted in Ontinue’s 2H 2024 Threat Intelligence Report, demonstrates the evolving sophistication of cyber attacks and the need for organizations to reassess their security strategies.

Browser Extensions: A New Vector for Malware Delivery

Attackers are exploiting browser extensions, particularly those on Chrome, to deliver information-stealing malware.

This method proves especially effective as malicious extensions can persist even after system reimaging.

Users inadvertently reintroduce the threat by reimporting their browser profiles, including infected extensions, during the recovery process.

Malvertising campaigns have also become more sophisticated, coercing users into executing malicious PowerShell commands.

These campaigns often guide users to open the ‘Run’ dialog using the Windows + R shortcut and paste commands using CTRL + V, bypassing traditional security measures.

Microsoft Tools Turned Against Users

Threat actors are increasingly abusing legitimate Microsoft tools like Quick Assist and Windows Hello to infiltrate systems and evade detection.

Quick Assist, a built-in Windows tool for remote support, is being exploited through social engineering tactics.

Attackers impersonate technical support personnel, convincing users to grant remote access to their devices.

Windows Hello, Microsoft’s passwordless authentication technology, has also become a target.

In misconfigured enterprise environments, attackers with valid user credentials can potentially enroll a new Windows Hello for Business device and authenticate without passwords, bypassing multi-factor authentication (MFA).

The report emphasizes the urgent need for organizations to reevaluate their security posture around trusted applications and authentication mechanisms.

Recommended measures include monitoring device registrations, enforcing strict conditional access policies, and implementing FIDO2 security keys for phishing-resistant authentication.

As these trends continue to evolve, cybersecurity teams must remain vigilant and adaptive in their approach to threat detection and mitigation.

The exploitation of trusted tools and extensions underscores the importance of comprehensive security strategies that account for both traditional and emerging attack vectors.

Find this Story Interesting! Follow us on LinkedIn, and X to Get More Instant Updates

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories