HomeSecurityRilide Chrome extension: Targets business users via PowerPoint guides

Rilide Chrome extension: Targets business users via PowerPoint guides

Rilide Chrome extension: Targets business users via PowerPoint guides

The malicious Rilide Stealer Chrome browser extension has returned in new campaigns targeting crypto users and business employees for stealing credentials and cryptocurrency wallets.

See also: New Rilide malware targets Chromium-based browsers to steal cryptocurrency

Rilide is a malicious browser extension for Chromium-based browsers, including Chrome, Edge, Brave, and Opera, which was originally discovered by Trustwave SpiderLabs in April 2023.

When it was first discovered, the Rilide browser extension masqueraded as legitimate Google Drive extensions to hijack the browser, monitor all user activity, and steal information such as email account credentials or cryptocurrency assets.

A new version of Rilide now supports Chrome Extension Manifest V3, allowing it to overcome the restrictions introduced by Google’s new extension specifications and adding additional code obfuscation to evade detection. In addition, the latest Rilide malware extension now also targets bank accounts and can wipe out stolen data via a Telegram channel or by taking screenshots at predetermined intervals and sending them to the C2 server.

Impersonating Palo Alto's extensions

According to Trustwave, Rilide is a malware sold on hacker forums and is spreading in multiple ongoing campaigns, likely run by different actors. One campaign targets multiple banks, payment service providers, email service providers, cryptocurrency exchanges, VPNs, and cloud service providers, primarily targeting users in Australia and the United Kingdom.

HSBC phishing page in the context of the Rilide campaign
HSBC phishing page in the context of the Rilide campaign

The analysts discovered over 1,500 phishing pages that use typosquatting domains, which are promoted via SEO poisoning on trusted search engines. These pages impersonate banks and service providers to trick victims into entering their account details into phishing forms. In another case, users get infected through phishing email messages that are purported to promote VPN applications or firewalls, such as the GlobalProtect application from Palo Alto.

In another case, users are infected with Rilide via phishing emails that purportedly promote VPN applications or firewalls, such as Palo Alto's GlobalProtect application. Trustwave found a PowerPoint presentation targeting ZenDesk employees that cleverly pretends to be a security warning, guiding users to install the extension.

PowerPoint document created to guide users in installing Rilide
PowerPoint document created to guide users in installing Rilide

The presentation includes slides that warn that the actors impersonate GlobalProtect to distribute malicious software and provides steps that the user must follow to install the correct software. However, this is actually a social engineering trick to convince the target user to install instead’ this malicious Rilide extension.

Finally, Trustwave detected a campaign running on Twitter, leading victims to phishing sites for fake blockchain P2E (Play To Earn) games. However, the installers on those sites install the Rilide extension instead’ allowing the actors to steal the victims' cryptocurrency wallets.

Infection chains for three Rilide campaigns
Infection chains for three Rilide campaigns

Suggestion: Compromised sites spread malware via fake Chrome updates

Regardless of the distribution campaign, during installation, the extension communicates with the actors' server and receives one of the following commands:

extension – Enable or disable an extension from the list of installed extensions.

Info – Send system and browser information to the C2 server. Retrieve all configuration settings.

Push – Create a notification with a specified message, title, and icon. Clicking on the notification will open a new tab with a URL from the C2 server.

Cookies – Download all browser cookies and send them to the C2 server.

Screenshot – Captures the visible area of ​​the currently active tab in the current window.

url – Create a new tab with the provided URL.

current_url – Retrieve the URL from the active tab.

History – Download browsing history from the last 30 days.

Injects – Retrieve injection code to apply to specific URLs.

Settings – Retrieve proxy, grabbers and telegram settings.

Proxy – Enable or disable proxy. The attackers use the proxy implementation from the 'CursedChrome' tool which allows web browsing while authenticating as the victim.

screenshot_rules – Updates the list of rules for the screenshot collection module at specified intervals.

With this extensive set of commands, the actors can steal a wide range of information that can then be used in crypto wallets and gain access to their online accounts.

Bypassing Manifest V3

Rilide is an extension that had to be adapted to Google’s new Manifest V3 standard, which prevents older extensions from stopping functioning from January 2023. Manifest V3 limits the extension’s access to the user’s network requests, prevents loading code from remote sources, and moves all modifications of network requests from extensions to the browser. This affects Rilide, as it relies on injection of remote JS scripts that are hosted remotely. Its developers had to implement a combination of published techniques that bypass Google’s requirements, such as using inline events to execute malicious JavaScript and abusing the Declarative Net Requests APIs to circumvent the XSS mitigation mechanism implemented by the Content Security Policy (CSP). Given that Rilide is not distributed through the Chrome Web Store, where Manifest V3 policies are strictly enforced, its developers can implement workarounds to execute code that is hosted remotely.

Rilide Chrome extension: Targets business users via PowerPoint guides
Full functional diagram of Rilide

Becoming increasingly popular among hackers

According to Trustwave researchers, the Rilide malware is sold for $5,000 to cybercriminals, who must devise their own distribution method, resulting in the use of multiple droppers for Rilide. Additionally, there have been several leaks of possibly authentic Rilide source code on underground forums, exposing the malware's source code to many hackers. This adds variety to the market and makes Rilide campaigns harder to map and detect. As the original author of the malware continues to improve the malicious Chrome extension, Rilide activity is unlikely to decrease.

Read also: Hackers target air-gapped devices in Eastern Europe with new malware

source of information:bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS