Chrome Extensions Target Hr Platforms
Executive Summary
Malicious Chrome extensions, posing as productivity and security tools, targeted enterprise HR and ERP platforms to steal authentication credentials. The extensions blocked access to security management pages, hindering incident response.
Key TTPs
- Initial Access: Masquerading as legitimate productivity and workflow tools on the Chrome Web Store.
- Execution: Stealing authentication tokens and session hijacking via cookie exfiltration and injection.
- Defense Evasion: Blocking access to security and incident response pages within targeted platforms.
Campaign Analysis
The extensions exfiltrated cookies every 60 seconds to attacker-controlled servers, maintaining persistent access. The attackers could take over authenticated sessions without needing usernames, passwords, or multi-factor authentication.
Targeting & Infrastructure
- Target Profile: Enterprise HR and ERP platforms such as Workday, NetSuite, and SAP SuccessFactors.
- Infrastructure: Use of multiple developer accounts to publish extensions with identical code and infrastructure patterns.
Relevant Terms
- Session Hijacking: Exploiting a valid computer session to gain unauthorized access to information or services.
- DOM (Document Object Model): A programming interface for HTML and XML documents that represents the page structure, allowing programs to modify the content.
Source: Bleeping Computer
