LayerX Reveals 40+ Malicious Browser Extensions

🚨 Overview

DomainTools and LayerX collaborated to uncover over 40 malicious Chrome extensions that serve dual purposes:

  • Masquerading as legitimate tools like VPNs, crypto tools, productivity apps
  • Acting as phishing tools and persistent access points for attackers

🧪 Origin of Discovery

  • DomainTools’ Threat Intelligence team detected malicious infrastructure via DNS and domain behavior analytics
  • Initial detection occurred through suspicious domains like calendly-daily[.]com, aiwriter[.]expert, etc.
  • Further analysis showed these domains were linked to browser extensions communicating with them regularly

📡 C2 Infrastructure & TTPs

  • All extensions phone home to attacker-controlled domains
  • Common TTPs (tactics, techniques, procedures) included:
    • Brand impersonation using cloned extension pages
    • AI-generated content for scalability
    • Consistent publisher email patterns (e.g. support@[domain])

🎭 Dual Function: Utility + Exploitation

These extensions offer seemingly useful functions like PDF converters, crypto trackers, or calendar apps — while simultaneously:

  • Tracking keystrokes and clipboard data
  • Capturing tokens/session data
  • Redirecting users to phishing pages

🧠 LayerX Extension Analysis

LayerX investigated each browser extension by:

  • Collecting extension IDs, names, publishers, and metadata
  • Cross-referencing permissions and update timestamps
  • Identifying overlapping infrastructure and branding

📋 List of Malicious Extension IDs

Extension IDExtension NamePublisher
ccollcihnnpcbjcgcjfmabegkpbehnipFortiVPNhttps://forti-vpn[.]com/
aeibljandkelbcaaemkdnbaacppjdmomManus AI | Free AI Assistanthttps://manusai[.]sbs
fcfmhlijjmckglejcgdclfneafoehafmSite Statshttps://sitestats[.]world
abbngaojehjekanfdipifimgmppiojplClothing Brand Name Generatorhttps://clothingbrandnamegenerator[.]app
dohmiglipinohflhapdagfgbldhmoojlDeBank – Digital Assetswinchester[.]abram37
acmiibcdcmaghndcahglamnhnlmcmlngAML Sector | Free Crypto AML Checkerhttps://amlsector[.]com
mipophmjfhpecleajkijfifmffcjdiacCrypto Whales Visionhttps://cryptowhalesvision[.]world
cknmibbkfbephciofemdjndbgebggnkcCalendly Dailyhttps://calendly-daily[.]com
gmigkpkjegnpmjpmnmgnkhmoinpgdnfcCalendly Dockethttps://calendly-docket[.]com
ahgccenjociolkbpgbfibmfclcfnlaeiCreativeHunter – Free tool for Facebookhttps://creativehunter[.]world
kjhjnbdjonamibpaalanflmidplhieheTwin Webhttps://twin-web[.]world
pobknfocgoijjmokmhimkfhemcnigdjiEventSpherehttps://eventphere[.]com
iclckldkfemlnecocpphinnplnmijkolSQLite browserhttps://sqlitebrowser[.]app
jmpcodajbcpgkebjipbmjdoboehfidddDeepSeek AI Chathttps://ai-chat-bot[.]pro
ihdnbohcfnegemgomjcpckmpnkdgoponAI Sentence Rewriterhttps://ai-sentence-rewriter[.]com
oeefjlikahigmlnplgijgeeecbpemhipConvert PDF to JPGhttps://pdf-to-jpg[.]app
aofddmgnidinflambjlfkpboeamdldbdHTML validatorhttps://htmlvalidator[.]app
acchdggcflgidjdcnhnnkfengdcmldaeCMS Checkerhttps://cmschecker[.]app
albakpncdngcejcjdahomfbkakbmafgbHourly to salary calculatorhttps://hourlytosalarycalculator[.]app
hhlcpmdhlcoghhfgiiopcjbkfmdlikncCSS validatorhttps://cssvalidator[.]app
eheagnmidghfknkcaehacggccfiidhikEmail checkerhttps://email-checker[.]pro
ckcfkaikieiicfdeomgehmnjglnofhdeCrypto Whale Alerthttps://crypto-whale[.]top
pbpobpjppnecgcinajfpaninmjkdbidmWeb Analyticshttps://web-analytics[.]top
gdfjahfbaillhkeigeinoomhjnfajbonAd Visionhttps://ad-vision[.]click
eoalbaojjblgndkffciljmiddhgjdldhMadgicx Plushttps://madgicx-plus[.]com
odhmhkkhpibfjijmpgcdjondompgocogSimilar Nethttps://similar-net[.]com
ohhhngpnknpdhmdmpmoccgjmmkkleipnMeta Spyhttps://meta-spy[.]help
nejfdccopmpimplhmmdfjobodgeaoihdFree VPN – Raccoonhttps://raccoon-vpn[.]world
dhhmopcmpiadcgchhhldcpoeppcofdicFree VPN – Orchidhttps://orchid-vpn[.]com
ffmfnniephcagojkpjddjiogjeoijjglVPN Free – Soul VPNhttps://soul-vpn[.]com
nabbdpjneieneepdfnmkdhooellilghoWebsite monitoringhttps://websitemonitoring[.]pro
mldeggofnfaiinachdeidpecmflffoamAI Writerhttps://aiwriter[.]expert
pndmbpnfolikhfnfnkmjkkpcgkmaibecAI Ad Generatorhttps://aiadgenerator[.]app
elipckbifniceedgalakgnmgeimfdcdiHeadline Generatorhttps://headlinegenerator[.]app
kkgmdjjpobmenpkhcclceelekpbnnanaWeb Watchhttps://webwatch[.]world
dcnjgfafcnopabhpgoekkgckgkkddpjgYouTube Visionhttps://youtube-vision[.]world
mllkmmdaapekjehapekhjjiednchgmagWeb Metricshttps://web-metrics[.]link
bhahpmoebdipfoaadcclkcnieeokebnfBitcoin price livehttps://bitcoin-price[.]live
oliiideaalkijolilhhaibhbjfhbdcnmLink shortenerhttps://u99[.]pro

For the official source and future updates, visit: LayerX Security Blog

Leave a Reply

Your email address will not be published. Required fields are marked *