{"id":1907,"date":"2025-06-08T11:01:00","date_gmt":"2025-06-08T08:01:00","guid":{"rendered":"https:\/\/trustcrypt.com\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025\/"},"modified":"2025-06-08T11:01:00","modified_gmt":"2025-06-08T08:01:00","slug":"malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025","status":"publish","type":"post","link":"https:\/\/trustcrypt.com\/ar\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025\/","title":{"rendered":"Malicious Browser Extensions Compromise Security of Over 700 Users Throughout Latin America Since Early 2025"},"content":{"rendered":"<p>Cybersecurity researchers have identified an ongoing campaign targeting users in Brazil since the beginning of 2025. This campaign involves the distribution of a malicious extension for Chromium-based web browsers aimed at exfiltrating user authentication data.<\/p>\n<p>As reported by Positive Technologies researcher Klimentiy Galkin, the attackers have employed phishing emails sent from compromised company servers to enhance the effectiveness of their strategy. The malicious extension has been reported to impact Google Chrome, Microsoft Edge, and Brave browsers, alongside other tools like Mesh Agent and PDQ Connect Agent.<\/p>\n<p>Positive Technologies has labeled this operation <strong>Operation Phantom Enigma<\/strong>. They found that the malicious extension was downloaded 722 times from various countries, including Brazil, Colombia, the Czech Republic, Mexico, Russia, and Vietnam. Approximately 70 distinct victim organizations have been identified. Initial details of the campaign were shared by a researcher known as <a href=\"https:\/\/x.com\/johnk3r\/status\/1907837072750063687\" rel=\"noopener\" target=\"_blank\">@johnk3r<\/a> in April.<\/p>\n<p>The attack mechanism begins with phishing emails, which masquerade as invoices and initiate a multi-stage process to install the browser extension. Recipients are persuaded to download a file via an embedded link or to open a malicious attachment within an archive.<\/p>\n<p>Embedded within these files is a batch script that is responsible for downloading and executing a PowerShell script. This script performs various checks, including assessing whether it operates within a virtualized environment and verifying the presence of Diebold Warsaw software.<\/p>\n<p>Diebold Warsaw, developed by GAS Tecnologia, is a security plugin designed to secure online banking and e-commerce transactions across Brazil. Notably, Latin American banking trojans like Casbaneiro have adopted similar functionalities, as previously disclosed by ESET in 2019.<\/p>\n<p>The PowerShell script is engineered to disable User Account Control (UAC), configure persistence by ensuring the batch script executes automatically upon system reboot, and establish a connection with a remote server for executing additional commands.<\/p>\n<p>The supported command set comprises:<\/p>\n<ul>\n<li>PING &#8211; Sends a heartbeat to the server and responds with &#8220;PONG&#8221;<\/li>\n<li>DISCONNECT &#8211; Terminates the active script process on the victim&#8217;s system<\/li>\n<li>REMOVEKL &#8211; Uninstalls the script<\/li>\n<li>CHECAEXT &#8211; Verifies the existence of the malicious browser extension in the Windows Registry, returning OKEXT if found, or NOEXT if absent<\/li>\n<li>START<em>SCREEN &#8211; Installs the extension by amending the <a href=\"https:\/\/chromeenterprise.google\/policies\/?policy=ExtensionInstallForcelist\" rel=\"noopener\" target=\"<\/em>blank&#8221;>ExtensionInstallForcelist<\/a> policy, which specifies applications and extensions that can be installed without user consent<\/em><\/li>\n<\/ul>\n<p>Identified extensions (with identifiers nplfchpahihleeejpjmodggckakhglee, ckkjdiimhlanonhceggkfjlmjnenpmfm, and lkpiodmpjdhhhkdhdbnncigggodgdfli) have been removed from the Chrome Web Store.<\/p>\n<p>Alternative attack vectors involve replacing the initial batch script with Windows Installer and Inno Setup files to deliver the malicious extensions. According to Positive Technologies, the extension is capable of executing harmful JavaScript code when the active browser tab is linked to Banco do Brasil.<\/p>\n<p>The extension transmits the user\u2019s authentication token back to the attackers\u2019 server and awaits commands that could instruct the victim\u2019s browser to display a deceptive loading screen (WARTEN or SCHLIEBEN<em>WARTEN) or present a malicious QR code on the bank\u2019s web page (CODE<\/em>ZUM_LESEN). The inclusion of German terminology may suggest the attackers&#8217; location or indicate that this code has been recycled from prior operations.<\/p>\n<p>In a bid to increase their pool of potential victims, the attackers leveraged invoice-related tactics to distribute installer files and deploy remote access tools such as MeshCentral Agent or PDQ Connect Agent instead of a malicious browser extension.<\/p>\n<p>Positive Technologies has also reportedly discovered an open directory associated with the attackers, containing links and parameters that revealed the EnigmaCyberSecurity identifier.<\/p>\n<p>Galkin emphasized that this study illuminates the deployment of unique techniques within Latin America, encompassing both a malicious browser extension and installations via Windows Installer and Inno Setup. The evidence of files within the attackers&#8217; accessible directory indicates a calculated effort to discreetly distribute emails by masquerading as compromised companies. However, the central objective of the attacks focuses predominantly on regular users in Brazil, aiming primarily to harvest their banking authentication credentials.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have identified an ongoing campaign targeting users in Brazil since the beginning of 2025. This campaign involves the&#8230;<\/p>\n","protected":false},"author":1,"featured_media":1908,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"Default","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[28],"tags":[154,237,77],"class_list":["post-1907","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-browser","tag-email","tag-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Malicious Browser Extensions Compromise Security of Over 700 Users Throughout Latin America Since Early 2025 - Trustcrypt<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustcrypt.com\/ar\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025\/\" \/>\n<meta property=\"og:locale\" content=\"ar_AR\" \/>\n<meta property=\"og:locale:alternate\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Malicious Browser Extensions Compromise Security of Over 700 Users Throughout Latin America Since Early 2025\" \/>\n<meta property=\"og:description\" content=\"Cybersecurity researchers have identified an ongoing campaign targeting users in Brazil since the beginning of 2025. This campaign involves the...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/trustcrypt.com\/ar\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025\/\" \/>\n<meta property=\"og:site_name\" content=\"Trustcrypt\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-08T08:01:00+00:00\" \/>\n<meta name=\"author\" content=\"Trustscrypt\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629\" \/>\n\t<meta name=\"twitter:data1\" content=\"Trustscrypt\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 \u062f\u0642\u0627\u0626\u0642\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/trustcrypt.com\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025\/\",\"url\":\"https:\/\/trustcrypt.com\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025\/\",\"name\":\"Malicious Browser Extensions Compromise Security of Over 700 Users Throughout Latin America Since Early 2025\",\"isPartOf\":{\"@id\":\"https:\/\/trustcrypt.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/trustcrypt.com\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/trustcrypt.com\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025.webp\",\"datePublished\":\"2025-06-08T08:01:00+00:00\",\"author\":{\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f\"},\"inLanguage\":\"ar\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/trustcrypt.com\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\/\/trustcrypt.com\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025\/#primaryimage\",\"url\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025.webp\",\"contentUrl\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025.webp\",\"width\":1792,\"height\":1024,\"caption\":\"Malicious Browser Extensions Compromise Security of Over 700 Users Throughout Latin America Since Early 2025\"},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/trustcrypt.com\/#website\",\"url\":\"https:\/\/trustcrypt.com\/\",\"name\":\"Trustcrypt\",\"description\":\"\u0627\u0644\u0623\u0645\u0646 \u0647\u0648 \u0627\u0633\u0645\u0646\u0627 \u0627\u0644\u062b\u0627\u0646\u064a\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/trustcrypt.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"ar\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f\",\"name\":\"Trustscrypt\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g\",\"caption\":\"Trustscrypt\"},\"sameAs\":[\"http:\/\/trustcrypt.com\"],\"url\":\"https:\/\/trustcrypt.com\/ar\/author\/trustscrypt\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Malicious Browser Extensions Compromise Security of Over 700 Users Throughout Latin America Since Early 2025 - Trustcrypt","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustcrypt.com\/ar\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025\/","og_locale":"ar_AR","og_type":"article","og_title":"[:en]Malicious Browser Extensions Compromise Security of Over 700 Users Throughout Latin America Since Early 2025[:] - Trustcrypt","og_description":"Cybersecurity researchers have identified an ongoing campaign targeting users in Brazil since the beginning of 2025. This campaign involves the...","og_url":"https:\/\/trustcrypt.com\/ar\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025\/","og_site_name":"Trustcrypt","article_published_time":"2025-06-08T08:01:00+00:00","author":"Trustscrypt","twitter_card":"summary_large_image","twitter_misc":{"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629":"Trustscrypt","\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631":"3 \u062f\u0642\u0627\u0626\u0642"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustcrypt.com\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025\/","url":"https:\/\/trustcrypt.com\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025\/","name":"Malicious Browser Extensions Compromise Security of Over 700 Users Throughout Latin America Since Early 2025","isPartOf":{"@id":"https:\/\/trustcrypt.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustcrypt.com\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025\/#primaryimage"},"image":{"@id":"https:\/\/trustcrypt.com\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025\/#primaryimage"},"thumbnailUrl":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025.webp","datePublished":"2025-06-08T08:01:00+00:00","author":{"@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f"},"inLanguage":"ar","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustcrypt.com\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025\/"]}]},{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/trustcrypt.com\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025\/#primaryimage","url":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025.webp","contentUrl":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/malicious-browser-extensions-compromise-security-of-over-700-users-throughout-latin-america-since-early-2025.webp","width":1792,"height":1024,"caption":"Malicious Browser Extensions Compromise Security of Over 700 Users Throughout Latin America Since Early 2025"},{"@type":"WebSite","@id":"https:\/\/trustcrypt.com\/#website","url":"https:\/\/trustcrypt.com\/","name":"Trustcrypt","description":"\u0627\u0644\u0623\u0645\u0646 \u0647\u0648 \u0627\u0633\u0645\u0646\u0627 \u0627\u0644\u062b\u0627\u0646\u064a","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustcrypt.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ar"},{"@type":"Person","@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f","name":"Trustscrypt","image":{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g","caption":"Trustscrypt"},"sameAs":["http:\/\/trustcrypt.com"],"url":"https:\/\/trustcrypt.com\/ar\/author\/trustscrypt\/"}]}},"_links":{"self":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts\/1907","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/comments?post=1907"}],"version-history":[{"count":0,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts\/1907\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/media\/1908"}],"wp:attachment":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/media?parent=1907"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/categories?post=1907"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/tags?post=1907"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}