HomeSecurityStealTok: Malicious extensions affect browser users

StealTok: Malicious extensions are affecting browser users

A widespread and particularly insidious malware campaign, known as “ StealTok ,” is bringing new risks to thousands of internet users. It is a network of at least 12 interconnected browser extensions that present themselves as tools to download videos from TikTok , but in reality act as surveillance and data collection mechanisms .

StealTok

LayerX 's research reveals that over 130,000 users have been affected globally , while thousands of installations remain active in popular ecosystems such as Google Chrome and Microsoft Edge.

The propagation mechanism and the attackers' strategy

The campaign's creators take a highly organized approach, constantly creating new versions or "clones" of the same extensions. Every time a version is detected and removed from the official stores, a new, slightly modified version.

This tactic ensures the continued presence of the malware, making it difficult to completely eliminate it. At the same time, the extensions initially function normally, offering the promised ability to download videos without watermarks, which reinforces their credibility.

In several cases, these applications even acquired a "featured" mark, increasing user trust and leading to mass installations.

See also: Attackers are abusing Microsoft Teams and targeting employees

Delayed activation: The most dangerous tactic

What makes the StealTok campaign particularly dangerous is the use of so-called delayed activation of malicious functions. For a period of up to a year, the extensions remain inactive in terms of malicious behavior.

During this period, they build positive reviews and successfully pass security checks. However, once they gain a sufficient user base, they activate hidden functions by connecting to remote command and control servers.

This technique allows attackers to turn a seemingly innocent extension into a spying tool, without requiring an update or reinstallation.

StealTok: Malicious extensions are affecting browser users

Data collection and digital footprint creation

Once activated, the extensions begin silently collecting user data . They monitor browsing activity , files downloaded, and various technical characteristics of the device.

The data collected includes time zone, language settings, and even battery status. While individually these elements may seem innocent, when combined they create a unique “digital fingerprint.”

This way, attackers can track users across different websites and services, even without the use of cookies.

See also: Apple's account change notifications send phishing emails

Hiding activity and techniques for avoiding detection

To evade detection, the extensions send data to deceptive domains that look legitimate but contain minor spelling errors. This technique makes it difficult for both users and automated systems to recognize malicious activity.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

StealTok highlights a major security flaw in browsers: assessment at installation time is no longer sufficient. As extensions can change behavior dynamically, the real threat appears much later.

Active threats and examples of extensions

Researchers found several active extensions related to the campaign. In Chrome, these included tools with thousands of installations, while corresponding versions were also found in Edge.

See also: Google: Gemini AI stops malicious ads

Some popular versions have already been removed, including extensions that had amassed tens of thousands of users. However, the constant updating of versions means that the threat remains active.

StealTok: Malicious extensions are affecting browser users

User protection and new security approaches

Experts recommend immediately uninstalling suspicious extensions and changing passwords on critical accounts. At the same time, it is suggested to adopt solutions based on continuous behavioral monitoring, both at the corporate and individual level.

The StealTok case clearly shows that the threat landscape is evolving. Attacks are no longer based solely on technical vulnerabilities, but also on user trust. In this environment, vigilance and understanding of the risks are the first line of defense.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS