Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
A Chrome extension that Google pulled from its store in January 2026 over conversation-theft allegations is back in circulation and reaching enterprise browsers again through Google’s own CRX distribution infrastructure... enterprise endpoints are currently receiving updates carrying a different kind of payload.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Detection name assigned by Netskope to the malicious Chrome extension update. The payload abuses extension update and uninstall events to open affiliate referral links, monetizing installs/removals and demonstrating the extension delivery channel could be used for more harmful payloads.
Detection name used by Netskope AV for the malicious 1.7.3.0 CRX build of the extension.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.