Chrome Extensions Infect 500K Users to Hijack VKontakte Accounts
A Chrome extension malware campaign has compromised over 500,000 VKontakte (VK) accounts. This operation involved hijacking accounts, forcing users into attacker-controlled groups, and resetting settings every 30 days. The campaign exploited VK’s…
A Chrome extension malware campaign has compromised over 500,000 VKontakte (VK) accounts. This operation involved hijacking accounts, forcing users into attacker-controlled groups, and resetting settings every 30 days. The campaign exploited VK’s infrastructure as command-and-control.
The malware was disguised as VK customization tools, managed by a single threat actor via GitHub. The initial detection occurred when a browser risk engine identified a Chrome extension injecting Yandex display ad scripts, a behavior often linked to monetization.
Researchers identified an extension named “VK Styles Themes for vk.com,” with approximately 400,000 installations. This extension contained a dynamically computed Yandex metric ID used to evade detection. This ID led to the discovery of five related extensions, totaling around 502,000 installations. Two of these extensions have been removed from the Chrome Web Store.
The VK Styles extension featured a multi-stage architecture. It utilized arbitrary code execution and a covert control hub through a VK profile. The malware extracted configuration data from HTML meta tags on the VK profile, which included encoded endpoints for GitHub Pages, Yandex advertising scripts, and ad-bundle hosting at Yandex’s infrastructure.
The extension did not hardcode URLs; instead, it fetched VK profile data, parsed meta tags, and downloaded the next-stage payload from GitHub. This approach allowed for flexible configuration, making it challenging to block without affecting legitimate VK traffic.
A Chrome extension malware campaign has compromised over 500,000 VKontakte (VK) accounts.
Auto-subscribed users to VK groups with a high probability, turning compromised accounts into a growth engine for attacker-controlled groups. Implemented a 30-day reset mechanism to maintain control over user settings. Manipulated VK’s CSRF protection cookie to legitimize extension-driven requests. Tracked donation status via VK Donut, monetizing hijacked accounts. Utilized a multi-stage architecture, allowing real-time behavior updates without changing the extension package.
Extension ID Install Count
ceibjdigmfbbgcpkkdpmjokkokklodmc 400,000
mflibpdjoodmoppignjhciadahapkoch 80,000
lgakkahjfibfgmacigibnhcgepajgfdb 20,000
bndkfmmbidllaiccmpnbdonijmicaafn 2,000
pcdgkgbadeggbnodegejccjffnoakcoh 2,000
Based on reporting by GBHackers.
