Malware News Fake Bitwarden ads on Facebook push info-stealing Chrome extension

Gandalf_The_Grey

Level 84
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
7,414
Fake Bitwarden password manager advertisements on Facebook are pushing a malicious Google Chrome extension that collects and steals sensitive user data from the browser.

Bitwarden is a popular password manager app with a "free" tier featuring end-to-end encryption, cross-platform support, MFA integration, and a user-friendly interface.

Its user base has been growing steadily in the past couple of years, especially following security breaches of competitors that led many to look for alternatives.

A new malvertising campaign impersonating Bitwarden was spotted by Bitdefender Labs, whose researchers report that the operation launched on November 3, 2024.
 

TairikuOkami

Level 37
Verified
Top Poster
Content Creator
Well-known
May 13, 2017
2,685
More extensions, more attack surface.
True, but a password manager can prevent auto-filling the password on a phishing webpage, then again auto-filling in an iframe might help to steal the password?! I give up. 😩
Attackers guide users through a process to install the extension by:
  • Unzipping the file
  • Going to their browser’s extension settings via chrome://extensions
  • Enabling Developer Mode
  • Manually loading the unpacked extension (sideloading).
Yeah, I see nothing suspicious about that process. I guess most people would just give up, because it is not click to install.
Also using good dns is another solution or layer.
Good thing I have Google dedicated browser. 😁
capture_11192024_140548.jpg
 
  • Like
Reactions: Thales

oldschool

Level 85
Verified
Top Poster
Well-known
Mar 29, 2018
7,698
True, but a password manager can prevent auto-filling the password on a phishing webpage, then again auto-filling in an iframe might help to steal the password?!
Users can keep unimportant passwords in browser's password manager, and then enable "Fill passwords on account selection" flag. Use the little black book for important passwords and manually input.
 
  • Like
Reactions: lokamoka820

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top