According to Koi Security, which discovered the GhostPoster campaign, the Firefox add-ons have been downloaded more than 50,000 times. The add-ons are no longer available.
See also: RomCom: SocGholish Fake Update attacks to distribute Mythic Agent

These browsers were advertised as VPNs, screenshot tools, ad blockers, and unofficial versions of Google Translate. The oldest add-on, Dark Mode, was released on October 25, 2024, offering the ability to enable a dark theme for all websites. The full list of add-ons includes:
- – Weather (weather-best-forecast)
- – Mouse Gesture (crxMouse)
- – Cache
- – Fast site loader
- – Google Translate (google-translate-right-clicks)
- – Global VPN
- –Free Forever
- – Dark Reader Dark Mode
- – Translator
- – Google Bing Baidu DeepL
- – Weather (i-like-weather)
- – Google Translate (google-translate-pro-extension)
- – libretv-watch-free-videos
- – Ad Stop
- – Best Ad Blocker
- – Google Translate (right-click-google-translate)
“What they really offer is a multi-stage malicious payload that tracks everything you browse, removes browser security protections, and opens a backdoor for remote code execution,” security researchers Lotan Sery and Noga Gouldman.
See also: Battlefield 6: Fake versions distribute infostealer

The attack chain begins when the logo file is retrieved when one of the aforementioned plugins is loaded. The malicious code parses the file for a pointer containing the “===” symbol to extract JavaScript code, a loader that communicates with an external server (“www.liveupdt[.]com” or “www.dealctr[.]com”) to retrieve the main payload, waiting 48 hours between each attempt.
To avoid detection, the loader is configured to retrieve the payload only 10% of the time. This randomness is a deliberate choice introduced to circumvent network traffic monitoring efforts. The retrieved payload is a custom coded full-featured tool capable of exploiting browsing activities without the victims' knowledge through four different methods.
In addition to probability checks, the add-ons also incorporate time delays that prevent the malware from activating until more than six days have passed since installation. These layered evasion techniques make it harder to detect what’s going on in the background.
It is worth emphasizing here that not all of the above plugins use the same steganography attack chain, but they all exhibit the same behavior and communicate with the same command and control (C2) infrastructure, indicating that this is the work of a single threat actor or group that has experimented with different decoys and methods.
See also: Iranian hackers target Israel with MuddyViper backdoor

The development comes just days after it was discovered that a popular VPN extension for Google Chrome and Microsoft Edge was secretly collecting AI conversations from ChatGPT, Claude, and Gemini and exporting them to data brokers. In August 2025, another Chrome extension named FreeVPN.One was observed collecting screenshots, system information, and user locations.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
