HomeSecurityGlassWorm malware hides RAT in Chrome extension

GlassWorm malware hides RAT in Chrome extension

Cybersecurity researchers have identified a new evolution of the GlassWorm campaign, which delivers a multi-stage framework capable of extensive data theft and installation of a remote access trojan (RAT). This, in turn, deploys a Google Chrome extension that steals information and pretends to be an offline version of Google Docs.

GlassWorm malware

“ It logs keystrokes, discards cookies and session tokens, captures screenshots, and receives commands from a C2 server hidden on a Solana blockchain ,” Aikido security researcher Ilyas Makari said .

Malicious operation “GlassWorm”

GlassWorm is the nickname given to a long-running campaign that gained initial traction through malicious packages published on platforms such as npm, PyPI, GitHub, and the Open VSX marketplace. In addition, operators have been known to compromise project administrator accounts to push out infected updates.

See also: DarkSword exploit leaked on GitHub

The attacks are careful enough to avoid infecting systems with Russian locale and use Solana transactions as a dead drop resolver to recover the command and control (C2) server and download payloads, specifically for the operating system.

The second stage of the payload is a data theft framework with capabilities to collect credentials, extract cryptocurrency wallets , and system profiles. The stolen data is compressed into a ZIP file and exported to an external server. It also incorporates functionality to retrieve and launch the final payload.

Once the data is transmitted, the attack chain involves retrieving two additional components: a .NET binary designed to perform hardware wallet phishing and a Websocket-based JavaScript RAT for stealing browser data and executing arbitrary code. The RAT payload is retrieved from a server using a public Google Calendar event URL as a dead drop resolver.

GlassWorm malware hides RAT in Chrome extension

The .NET binary exploits the Windows Management Instrumentation (WMI) infrastructure to detect USB device connections and displays a phishing window when a Ledger or Trezor hardware wallet.

“The Ledger UI displays a fake configuration error and presents 24 numbered recovery phrase entry fields,” Makari noted. “The Trezor UI displays a fake ‘Firmware validation failed, emergency boot’ message with the same 24-word layout. Both windows include a ‘RESTORE WALLET’ button.”

See also: North Korean hackers abuse VS Code's automated tasks

The malware not only terminates any actual Ledger Live processes running on the Windows host, but also re-displays the phishing window if the victim closes it. The ultimate goal of the attack is to capture the wallet's recovery phrase and broadcast it to an IP address.

The RAT, on the other hand, uses a Distributed Hash Table (DHT) to retrieve the C2 details. In case the mechanism does not return any value, the malware switches to the Solana-based dead drop. The RAT then establishes communication with the server to execute various commands on the compromised system:

– start_hvnc / stop_hvnc, to deploy a hidden Virtual Network Computing (HVNC) module for remote desktop access.

– start_socks / stop_socks, to start a WebRTC module and operate it as a SOCKS proxy.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

– reget_log, for stealing data from web browsers such as Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Vivaldi, and Mozilla Firefox. The component is equipped to bypass encryption protections associated with the Chrome application.

– get_system_info, to send system information.

– command, to execute JavaScript provided by the attacker via eval().

GlassWorm malware hides RAT in Chrome extension

Installation of malicious Chrome extension

The RAT also forcibly installs a Google Chrome extension called Google Docs Offline on Windows and macOS systems, which then connects to a C2 server and receives commands to collect cookies, localStorage, the full Document Object Model (DOM) tree of the active tab, bookmarks, screenshots, keystrokes, clipboard content, up to 5,000 browser history entries, and the list of installed extensions.

See also: VoidStealer malware steals passwords – Chrome ABE bypass

“The extension also performs targeted session. It takes the monitored site rules from /api/get-url-for-watch and sends them with Bybit (.bybit.com) preconfigured as the target, monitoring the secure-token and deviceid cookies,” Aikido said. “Upon detection, it triggers a user-detected webhook at /api/webhook/auth-detected, which contains the cookie material and page metadata. The C2 can also provide redirect rules that direct active tabs to attacker-controlled URLs.”

Protection

Developers are advised to be cautious when installing Open VSX extensions, npm packages, and MCP servers. It is also recommended to verify publisher names, package history, and avoid blindly trusting download counts. Polish cybersecurity firm AFINE has published an open-source Python tool called glassworm-hunter to scan developers' systems for campaign-related payloads.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS