Sunday, January 24, 2021
  • About
  • Advertise
  • Careers
Scoftware Magazine
  • Home
  • Politics
  • Business
  • Culture
  • Opinion
  • Lifestyle
  • Entertainment
  • Login
No Result
View All Result
Scoftware Magazine
Home Tech

Massive spying on Google Chrome users shows new security weakness

Jaleel M. by Jaleel M.
June 18, 2020
in Tech
0
Massive spying on Google Chrome users shows new security weakness
0
SHARES
4
VIEWS
Share on FacebookShare on Twitter


Alphabet Inc’s Google said it removed more than 70 of the malicious add-ons from its official Chrome Web Store after being alerted by the researchers last month.

“When we are alerted of extensions in the Web Store that violate our policies, we take action and use those incidents as training material to improve our automated and manual analyses,” Google spokesman Scott Westover told Reuters.

Most of the free extensions purported to warn users about questionable websites or convert files from one format to another. Instead, they siphoned off browsing history and data that provided credentials for access to internal business tools.

Based on the number of downloads, it was the most far-reaching malicious Chrome store campaign to date, according to Awake co-founder and chief scientist Gary Golomb.

Google declined to discuss how the latest spyware compared with prior campaigns, the breadth of the damage, or why it did not detect and remove the bad extensions on its own despite past promises to supervise offerings more closely.

It is unclear who was behind the effort to distribute the malware. Awake said the developers supplied fake contact information when they submitted the extensions to Google.

“Anything that gets you into somebody’s browser or email or other sensitive areas would be a target for national espionage as well as organized crime,” said former National Security Agency engineer Ben Johnson, who founded security companies Carbon Black and Obsidian Security.

The extensions were designed to avoid detection by antivirus companies or security software that evaluates the reputations of web domains, Golomb said.

If someone used the browser to surf the web on a home computer, it would connect to a series of websites and transmit information, the researchers found. Anyone using a corporate network, which would include security services, would not transmit the sensitive information or even reach the malicious versions of the websites.

“This shows how attackers can use extremely simple methods to hide, in this case, thousands of malicious domains,” Golomb said.

All of the domains in question, more than 15,000 linked to each other in total, were purchased from a small registrar in Israel, Galcomm, known formally as CommuniGal Communication Ltd.

Awake said Galcomm should have known what was happening.

In an email exchange, Galcomm owner Moshe Fogel told Reuters that his company had done nothing wrong.

“Galcomm is not involved, and not in complicity with any malicious activity whatsoever,” Fogel wrote. “You can say exactly the opposite, we cooperate with law enforcement and security bodies to prevent as much as we can.”

Fogel said there was no record of the inquiries Golomb said he made in April and again in May to the company’s email address for reporting abusive behavior, and he asked for a list of suspect domains. Reuters sent him that list three times without getting a substantive response.

The Internet Corp for Assigned Names and Numbers, which oversees registrars, said it had received few complaints about Galcomm over the years, and none about malware.

While deceptive extensions have been a problem for years, they are getting worse. They initially spewed unwanted advertisements, and now are more likely to install additional malicious programs or track where users are and what they are doing for government or commercial spies.

Malicious developers have been using Google’s Chrome Store as a conduit for a long time. After one in 10 submissions was deemed malicious, Google said in 2018 it would improve security, in part by increasing human review.

But in February, independent researcher Jamila Kaya and Cisco Systems’ Duo Security uncovered https://duo.com/labs/research/crxcavator-malvertising-2020 a similar Chrome campaign that stole data from about 1.7 million users. Google joined the investigation and found 500 fraudulent extensions.

“We do regular sweeps to find extensions using similar techniques, code and behaviors,” Google’s Westover said, in identical language to what Google gave out after Duo’s report.

This story has been published from a wire agency feed without modifications to the text. Only the headline has been changed.

Subscribe to newsletters

* Enter a valid email

* Thank you for subscribing to our newsletter.

Topics



Source link

Related posts

US says Google breakup may be needed to end violations of antitrust law

US says Google breakup may be needed to end violations of antitrust law

October 21, 2020
Apple Music launches TV channel for music videos

Apple Music launches TV channel for music videos

October 20, 2020
Previous Post

What made goal-line technology err in English Premier League game

Next Post

S Sreesanth “Raring To Go” As Seven-Year Ban Nears End

Next Post
S Sreesanth “Raring To Go” As Seven-Year Ban Nears End

S Sreesanth "Raring To Go" As Seven-Year Ban Nears End

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

England vs West Indies 1st Test: When And Where To Watch Live Telecast, Live Streaming

England vs West Indies 1st Test: When And Where To Watch Live Telecast, Live Streaming

7 months ago
Facebook invites independent audit of its content review reports

Facebook invites independent audit of its content review reports

6 months ago
The MixtapE! Presents Lady Gaga, Ariana Grande, The 1975 and More

The MixtapE! Presents Lady Gaga, Ariana Grande, The 1975 and More

8 months ago
Dirty John’s Christian Slater & Amanda Peet on the “Horrible Tragedy” of Betty Broderick’s Story

Dirty John’s Christian Slater & Amanda Peet on the “Horrible Tragedy” of Betty Broderick’s Story

7 months ago

FOLLOW US

  • 79 Followers
  • 29.5k Followers
  • 82.6k Subscribers

BROWSE BY CATEGORIES

  • Business
  • Culture
  • Entertainment
  • Lifestyle
  • Music
  • National
  • News
  • Opinion
  • Politics
  • Sports
  • Tech
  • Travel
  • World News

BROWSE BY TOPICS

2018 League Balinese Culture Bali United Budget Travel Champions League Chopper Bike Doctor Terawan Istana Negara Market Stories National Exam Visit Bali

POPULAR NEWS

  • Kris Jenner Spills Details About Her Sex Life With Corey Gamble: Watch

    Kris Jenner Spills Details About Her Sex Life With Corey Gamble: Watch

    0 shares
    Share 0 Tweet 0
  • Common Saints Release New Single “Idol Eyes”

    0 shares
    Share 0 Tweet 0
  • KRISTIN LASH & JAKOB GREY Team Up On “Sleeping With The Lights On”

    0 shares
    Share 0 Tweet 0
  • Sam Heughan & Graham McTavish Are Men in Kilts for Travel Show

    0 shares
    Share 0 Tweet 0
  • A Blackhat Hacker Durgesh Singh Kushwah Tells Us All!

    0 shares
    Share 0 Tweet 0
  • About
  • Advertise
  • Careers

© 2020 Scoftware.com

No Result
View All Result
  • Home
  • Politics
  • Business
  • Culture
  • National
  • Sports
  • Lifestyle
  • Travel
  • Opinion

© 2020 Scoftware.com

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Terms and Conditions - Privacy Policy