DarkSpectre Browser Extension Campaigns Expose 8.8 Million Users to Corporate Espionage

DarkSpectre is a Chinese threat actor operating three browser extension campaigns infecting 8.8 million users across Chrome, Edge, and Firefox. ShadyPanda (5.6M users) executes mass surveillance and affiliate fraud. GhostPoster (1.05M) delivers steganographic payloads. The Zoom Stealer (2.2M) monitors 28+ video conferencing platforms, exfiltrating meeting URLs, participant lists, speaker identities, and company data in real-time. Extensions remain legitimate for years while accumulating millions of installations, then activate malicious behavior via server-side updates without review. This demonstrates why browser marketplace security models fail and how corporate espionage infrastructure operates at nation-state scale.

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

Article Link: DarkSpectre Browser Extension Campaigns Expose 8.8 Million Users to Corporate Espionage - Cyberwarzone

1 post - 1 participant

Read full topic



Malware Analysis, News and Indicators - Latest topics
Next Post Previous Post