131 Malicious Chrome Extensions Discovered Targeting WhatsApp Users
## Cybersecurity: Malicious Chrome Extensions Targeting WhatsApp Web
Cybersecurity: Malicious Chrome Extensions Targeting WhatsApp Web
Recent investigations by the Socket Threat Research Team have uncovered 131 malicious Chrome extensions designed to target WhatsApp Web users. These extensions, while not traditional malware, function as high-risk automation tools that violate platform policies to facilitate spam campaigns directed primarily at Brazilian users.
The operation centers on a single WhatsApp Web automation tool, which has been cloned and rebranded into 131 extensions. Despite different branding, all clones share identical codebases and backend infrastructures. Over 80 extensions are labeled as "WL Extensão" or similar, and have been published by two developer accounts associated with DBX Tecnologia and Grupo OPT.
131 cloned extensions of a WhatsApp Web automation tool. Extensions share the same codebase and infrastructure. Published through two developer accounts: suporte@grupoopt.com.br and kaio.feitosa@grupoopt.com.br. 83 extensions branded under WL Extensão and WLExtensao. Campaign active for at least nine months with updates planned through 2025.
The structure mirrors a franchise model where resellers pay a fee for a customizable extension build. DBX Tecnologia promotes this as a "white-label partnership" offering potential revenue streams for resellers.
Recent investigations by the Socket Threat Research Team have uncovered 131 malicious Chrome extensions designed to target WhatsApp Web users.
The extensions automate bulk messaging on WhatsApp Web, using features that bypass WhatsApp's anti-spam algorithms. They inject code into the WhatsApp Web page, operating alongside legitimate scripts to conduct unsolicited outreach.
Code injection into WhatsApp Web pages. Automated bulk messaging and scheduling to bypass anti-spam controls. Violations of Chrome Web Store policies against duplicate extensions and spam. Circumvention of WhatsApp’s Business Messaging policy requiring opt-in. False marketing claims regarding Chrome Web Store security audits.
The operation abuses Chrome Web Store policies, which forbid duplicate extensions and spam. It also circumvents WhatsApp's requirements for explicit user opt-in.
The 131 extensions have a combined user base of at least 20,905. Socket's AI security analysis has identified policy violations, and takedown requests have been submitted. Organizations and users should enhance security measures to mitigate risks, such as restricting Chrome extension installations, using inventory analysis tools, and monitoring for suspicious activities.
As bulk messaging spam increases, robust countermeasures are essential for those using WhatsApp for communication.
Based on reporting by GBHackers.
