Phoenix Invicta is a threat actor associated with malicious browser-extension activity in the Chrome Web Store. The group has been linked to extensions that abused Chrome Manifest V3 functionality, particularly declarativeNetRequest, to strip security headers such as Content-Security-Policy and Strict-Transport-Security from targeted web responses. This behavior can facilitate downstream content injection, weaken browser-enforced protections, and support session compromise and other post-compromise actions. Phoenix Invicta has been discussed in connection with a broader January 2025 campaign involving compromised or malicious browser extensions distributed through legitimate extension update channels. In that activity, attackers reportedly leveraged extension permissions and content-script execution to access authenticated web content and steal browser cookies, enabling session hijacking. The tradecraft associated with this ecosystem includes use of service-worker-based logic for command-and-control and configuration retrieval, injection of scripts across broad URL scopes, and abuse of extension auto-update mechanisms for rapid victim reach. The actor’s observed capabilities center on browser-based post-exploitation rather than traditional endpoint malware deployment. Reported behaviors include manipulation of HTTP response handling, observation and modification of web content through extension permissions, theft of cookies and authenticated sessions, and evasion through blending malicious traffic into normal browser activity. High-confidence reporting directly ties Phoenix Invicta to malicious extension behavior and security-header stripping; broader attribution for all related extension compromises should be treated cautiously unless independently corroborated.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.