Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Malicious ‘Sleeper Agent’ Browser Extensions Infected 1.5 Million Users Globally

LayerX has identified a network of malicious browser extensions, called "sleeper agents," installed on approximately 1.5 million devices globally. These extensions, which appear as legitimate sound management tools, share a codebase and infrastructure,…

LayerX has identified a network of malicious browser extensions, called "sleeper agents," installed on approximately 1.5 million devices globally. These extensions, which appear as legitimate sound management tools, share a codebase and infrastructure, suggesting development by a single entity.

Despite their benign appearance, these extensions possess hidden capabilities. They can execute remote commands, open background tabs, communicate with malicious domains, and use encryption and obfuscation techniques to evade detection by traditional security tools. This infrastructure allows attackers to activate malicious behavior, potentially turning users’ browsers into launchpads for cyberattacks.

Shared Malicious Codebase and Remote Command Execution

Analysis reveals similarities with previously removed malicious extensions, such as ReadBee (Extension ID: phjbepamfhjgjdgmbhmfflhnlohldchb). The core infrastructure includes the ExtStatTracker class, which tracks user activity and enables remote command execution. It encodes user data and sends it to external servers, like readrbee.com, and can open URLs in new tabs without user consent.

Below is a simplified overview of the ExtStatTracker class:

class ExtStatTracker { constructor() { this.installUrl = "https://readrbee.com/install/"; this.uninstallUrl = "https://readrbee.com/uninstall/"; this.uid = ""; this.version = chrome.runtime.getManifest().version; this.initStorage(); this.initListeners(); } processQueue() { // Sends encoded user data and executes remote commands // Opens arbitrary URLs via chrome.tabs.create() } setUninstallUrl() { // Sets uninstall URL with encoded user data } initListeners() { // Listens for install/update events and queues actions } initStorage() { // Retrieves and stores persistent user identifiers } } const extStatTracker = new ExtStatTracker;

Obfuscated Ownership and Widespread Impact

LayerX has identified at least four extensions involved in this campaign, focusing on sound management, with a user base exceeding 1.2 million. These extensions remain available on the Chrome Web Store, with publishers using anonymous identities, complicating attribution efforts.

LayerX has identified a network of malicious browser extensions, called "sleeper agents," installed on approximately 1.5 million devices globally.
Joseph Cain · Thehackingpost

Extension Name Extension ID Users

Sound Booster pmilcmjbofinpnbnpanpdadijibcgifc 200,000

Volume Max – Ultimate Sound Booster mgbhdehiapbjamfgekfpebmhmnmcmemg 1,000,000

Volume Master: Master Your Sound eoejmjkddfbhhnbmklhccnppogeaeeah 3,000

Advertisement

Volume Booster: Ultimate Sound Enhancer dlcgileladmbfijjmnleehhoebpggpjl 2,000

Some extensions have been flagged as malicious by security vendors but remain accessible. They communicate with domains like francjohn[.]com and jermikro[.]com, which have histories of malware activity.

The discovery of this network signals a shift in cybercriminal tactics. Instead of traditional botnets from compromised IoT devices, attackers use browser extensions for persistent, stealthy access to sensitive data, including cookies and passwords. The infrastructure allows for remote activation of malicious capabilities, highlighting the importance of continuous monitoring and vetting of browser extensions.

Security experts advise users and organizations to remain vigilant, regularly audit installed extensions, and treat even seemingly innocuous tools with caution, as the threat landscape evolves in sophistication and scale.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories