Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Google Play Apps Use Stealth Loaders to Deliver Anatsa Banking Malware
August 10, 2026
Fake Google Translate Chrome Extension Lets Attackers Control Browsers
August 10, 2026
CEVA Logistics Data Breach Exposes Valve Steam Hardware Buyers’ Information
August 10, 2026
Home/CyberSecurity News/Fake Google Translate Chrome Extension Lets Attackers Control Browsers
CyberSecurity News

Fake Google Translate Chrome Extension Lets Attackers Control Browsers

Key Takeaways A new malicious Chrome extension, disguised as Google Translate, has been discovered. This extension can steal extensive browser data, stream live web sessions, and allow remote control...

David kimber
David kimber
August 10, 2026 3 Min Read
1 0

Key Takeaways

  • A new malicious Chrome extension, disguised as Google Translate, has been discovered.
  • This extension can steal extensive browser data, stream live web sessions, and allow remote control of Chrome windows.
  • The attack chain involves a multi-stage infection, deploying an information stealer alongside the rogue extension.
  • A key feature allows attackers to operate browser windows in the background, out of the victim’s immediate view.

Sophisticated Chrome Extension Masquerades as Google Translate, Grants Attackers Deep Browser Control

Cybersecurity researchers have uncovered a highly sophisticated malicious Chrome extension that deceptively poses as Google Translate. This threat is capable of exfiltrating sensitive browser data, streaming victim web sessions in real-time, and enabling threat actors to interact with Chrome windows remotely without the user’s awareness.

Table Of Content

  • Key Takeaways
  • Sophisticated Chrome Extension Masquerades as Google Translate, Grants Attackers Deep Browser Control
  • Multi-Stage Infection Chain Unveiled
  • Extensive Data Theft and Remote Manipulation
  • Covert Operations and Man-in-the-Browser Attacks
  • The Danger of Trusted Branding
  • What You Should Do

Multi-Stage Infection Chain Unveiled

The attack initiates with a suspected Rust-based malware loader. VMRay researchers identified that this binary deploys two critical components: a malicious Chrome extension and an AutoIt script. This script then proceeds to install the Stealc v2 information-stealing malware, creating a robust, multi-faceted infection.

This intricate infection path provides adversaries with not only conventional endpoint data theft capabilities but also an unusually profound level of control over the compromised browser environment.

Extensive Data Theft and Remote Manipulation

Upon installation, the fraudulent extension begins harvesting a wide array of browser-resident data. This includes a user’s complete browsing history, saved bookmarks, details of other installed extensions, cookies, and stored credentials. Such comprehensive data allows attackers to hijack online accounts, circumvent session-based security measures, profile victims for future attacks, and pinpoint high-value targets such as email services, cryptocurrency platforms, cloud consoles, and corporate applications.

Perhaps the most alarming feature of this extension is its capacity to provide attackers with a live feed of Chrome windows, coupled with the ability to remotely operate websites using simulated mouse clicks and keyboard inputs. Essentially, the victim’s browser transforms into a remote control interface for the attacker. Chrome’s extension APIs are legitimately designed to interact with tabs and, when granted appropriate permissions, can access sensitive tab properties or inject scripts into matching websites. These permissions, however, become a significant vulnerability when users install an untrusted extension.

Covert Operations and Man-in-the-Browser Attacks

Unlike typical remote-access tools, this campaign is engineered for clandestine fraudulent activity. The extension reportedly enables remote control of browser windows that are not in focus. This means attackers can execute actions in the background while the victim is actively using another application or window, significantly reducing the likelihood of detection for unauthorized clicks, navigation, or form submissions within Chrome.

Researchers also noted functionalities for configuring a proxy and injecting attacker-controlled JavaScript into specific websites. Proxy configuration could reroute browser traffic through adversary-controlled infrastructure, while JavaScript injection can modify the content users view or manipulate sessions on targeted domains. These capabilities open avenues for account takeover, payment fraud, data theft, and highly targeted social engineering.

A further significant risk involves a sophisticated man-in-the-browser phishing technique. The extension can overlay a legitimate website with an iframe that displays content from an attacker-controlled phishing page. Crucially, the browser’s address bar may still show the genuine domain, tricking victims into believing they are interacting with a trusted login portal. Consequently, users might submit passwords, multi-factor authentication codes, or payment details directly to criminals, unaware that the visible form is fraudulent.

The Danger of Trusted Branding

The malicious use of Google Translate branding is particularly insidious, as translation extensions are commonplace, highly useful, and generally not perceived as high-risk by users. Threat actors have consistently exploited the perceived trustworthiness of browser add-ons to gain access to credentials, cookies, screenshots, and web sessions. A notable prior campaign, attributed to the Kimsuky threat actor, similarly utilized a Chrome extension named “GoogleTranslate.crx” to collect account and browser data.

What You Should Do

  • Immediately review all installed Chrome extensions. Remove any unfamiliar, unnecessary, or suspicious add-ons.
  • Carefully scrutinize permission requests from extensions, especially those seeking broad access to website data.
  • Organizations should implement policies to restrict unmanaged extensions and monitor for suspicious browser policy changes.
  • Enforce phishing-resistant multi-factor authentication (MFA) across all critical services to mitigate damage from stolen passwords and session data.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

CEVA Logistics Data Breach Exposes Valve Steam Hardware Buyers’ Information

Next Post

Google Play Apps Use Stealth Loaders to Deliver Anatsa Banking Malware

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Apple Private Cloud Compute Flaw Exposes AI Data, Enables Root Access
August 10, 2026
Critical VS Code Extension Steals Crypto Wallets, API Keys, SSH Keys
August 10, 2026
Kimsuky deploys AsyncRAT via AI lures, local LLMs, and GitHub C2
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us