New Version of Rilide Data Theft Malware Adapts to Chrome Extension Manifest V3

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,178
Cybersecurity researchers have discovered a new version of malware called Rilide that targets Chromium-based web browsers to steal sensitive data and steal cryptocurrency.

"It exhibits a higher level of sophistication through modular design, code obfuscation, adoption to the Chrome Extension Manifest V3, and additional features such as the ability to exfiltrate stolen data to a Telegram channel or interval-based screenshot captures," Trustwave security researcher Pawel Knapczyk said in a report shared with The Hacker News.

Rilide was first documented by the cybersecurity company in April 2023, uncovering two different attack chains that made use of Ekipa RAT and Aurora Stealer to deploy rogue browser extensions capable of data and crypto theft. It's sold on dark web forums by an actor named "friezer" for $5,000.

The malware is equipped with a wide range of features that allow it to disable other browser add-ons, harvest browsing history and cookies, collect login credentials, take screenshots, and inject malicious scripts to withdraw funds from various cryptocurrency exchanges.
 
Last edited:

Sandbox Breaker

Level 9
Verified
Well-known
Jan 6, 2022
435
Can this run on chrome OS is my first question. I see the kill chains contain windows based executable code. I'm assuming if they got the extension listed on the webstore combined with a screen locker/social engineering... They can get it to infect chromebooks also.

Google may now have a more serious problem on their hands. This thing runs in manifest 3! The Play Store is already roasting with malware and extensions ain't new. But this takes things to a new level.

I doubt that the extension can grad the stored passwords/secrets from the Titan C on chrome books as there is a biometric/password requirement. I could be wrong though. We will need to see how this plays out guys ! 🤞
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top