Kaspersky researchers reported that a browser extension presented as an ad blocker was distributed with hidden cryptocurrency-mining functionality. The extension appeared to offer a legitimate privacy and usability feature, but also consumed victim system resources to mine digital currency without clear user awareness or informed consent.
The finding highlights how seemingly benign browser add-ons can act as dual-use malware, blending expected functionality with covert monetization. For defenders, the case underscores the need to scrutinize extension permissions, monitor abnormal browser-driven CPU usage, and restrict unvetted add-ons in enterprise environments to reduce the risk of unauthorized mining and broader browser-based compromise.

Trace attribution and downstream blast radius.
1 event from the most recent confirmed update back to the earliest known activity.
Kaspersky Securelist published research describing an ad blocker that included cryptocurrency-mining functionality. No additional dated milestones are provided in the reference content, so the publication date is used as the event date.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.