HomeSecurityCursedChrome turns your browser into a proxy

CursedChrome turns your browser into a proxy

Last week, a security researcher published a proof-of-concept Chrome extension that turns Chrome browsers into proxy bots, allowing hackers to browse the web using the identity of an infected user. The tool, dubbed CursedChrome, was created by security researcher Matthew Bryant and released on GitHub as an open-source project.

Now, CursedChrome has two different parts – a client-side component (the Chrome extension itself) and a server-side counterpart (a dashboard where all CursedChrome bots report).

Once the extension is installed on some browsers, the attacker can log in to the CursedChrome control panel and establish a connection to any infected host.

The link between the extension and the control panel is a simple WebSocket connection that acts as a classic HTTP reverse proxy.

This means that once the attacker connects to an infected host, they can then browse the web using the infected browser and, in doing so, hijack logged-in sessions and online identities to access restricted areas, such as intranets or corporate applications.

A project like CursedChrome is the ideal tool for an attacker.

CursedChrome turns your browser into a proxy

CURSEDCHROME was created as a tool for pen-testers

However, in an interview last week, Bryant said it wasn't in his intentions.

“I opensourced the code because I want other professional red teamers and pen-testers to be able to accurately simulate the malicious browser extension scenario,” Bryant told us.

By the term red teamers, the researcher refers to cybersecurity professionals who are paid to break into companies. Their work is vital, as they report on what they find so companies can fix issues and keep hackers at bay.

The researcher also said that CursedChrome is nothing an attacker couldn't have built themselves. The project works on already existing technologies and doesn't bring any innovation to the table.

“Similar tools, such as Cobalt Strike's 'browser pivot' (for Internet Explorer) and the open source BeEF framework have been around for years, and the technical details of how to perform this attack are freely available online,” Bryant said.

Furthermore, Bryant isn't afraid that hackers might use his code. Weaponizing CursedChrome requires attackers to either (1) host the extension in the Chrome Web Store or (2) install it through a corporate policy or through Chrome's developer mode.

Bryant says the first scenario likely won't work since "the Web Store's extension control pipeline is extremely effective at keeping out potentially malicious extensions," while the second scenario requires the attacker to have access to network , by which point they already have full control and access to everything else.

Instead, the researcher said he wants to raise awareness about the issue of malicious Chrome extensions and the damage they can do in corporate environments.

The researcher says that by using something like CursedChrome, pen-testers can show companies how vulnerable they really are when they don't strictly control what employees on their browsers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS