A new malware service promises to bypass Google’s review process and bring its malware directly to the Chrome Store



  • Russian hackers sell Chrome extension service that bypasses Google Store moderation
  • Malicious plugin spoofs legitimate sites with full-screen iframes to steal credentials
  • Varonis recommends strict lists of authorized companies and consumer outreach audits for added protection

Russian hackers are selling a service that allows other criminals to spoof legitimate websites, tricking victims into exposing their login credentials, or possibly even making fraudulent bank transfers.

A threat actor alias ‘Stenli’ (Stanley) recently started offering a service that basically guarantees that a malicious Chrome extension will “pass Google Store moderation” and land in the browser’s add-on repository.



Leave a Comment

Your email address will not be published. Required fields are marked *