Turkish hackers tried to distribute malicious browser plugins by uploading them to the official Google Chrome store.
Kaspersky experts report that hackers have turned to this technique since Google added certain security mechanisms that prevent the silent installation of extensions.
In a scenario observed by Kaspersky, the attackers used Facebook to lure users to various websites hosted under domains .Tk . All these domains redirect their visitors to a fake Chrome information website.
If you choose to update your Chrome, these websites will give you instructions on how to do so and will prompt you to download plugins called “Chrome Guncellemesi”, or “Chrome Update” or “Flash Player 12.1” from the official Chrome Web Store.
Despite the fact that they are hosted on a legitimate Google site, the plugins are malicious and ask the user to give them permission to access all data that is related to the websites they visit.
Similar extensions have also been found for Firefox.
Google has been notified and the company is trying to keep the Chrome Web Store clean, which is somewhat difficult, as hackers always discover new ways to bypass security safeguards.

