Skip to main content

Threats Tagged 'trust exploitation'

View all threats tagged with 'trust exploitation'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: trust exploitation

Threats Tagged 'trust exploitation'

Click on any threat for detailed analysis and mitigation recommendations

The ShadyPanda threat actor has conducted a sophisticated seven-year malware campaign infecting 4.3 million Chrome and Edge browsers via malicious extensions that were verified and featured by Google, enabling widespread trust and distribution. The campaign operates two main components: a 300,000-user remote code execution (RCE) backdoor and a 4-million-user spyware operation that harvests extensive user data such as browsing history, search queries, and mouse clicks, sending it to servers in China. This malware exploits vulnerabilities in browser extension marketplaces and trusted update mechanisms to maintain persistence and evade detection. The campaign highlights significant risks to user privacy and organizational security, especially for entities relying heavily on Chrome and Edge browsers. European organizations face risks of data exfiltration, espionage, and potential lateral movement within networks. Mitigation requires proactive extension management, network monitoring for suspicious domains, and enhanced user awareness. Countries with high Chrome/Edge usage and strategic geopolitical interest in China-related cyber espionage are most at risk. The threat severity is assessed as high due to the scale, stealth, and potential impact on confidentiality and integrity without requiring user interaction post-installation.

Join the discussion

A coordinated campaign of 18 malicious browser extensions infected 2.3 million users across Chrome and Edge. These extensions, including a color picker tool, appeared legitimate with verified badges and high install counts. The RedDirection campaign implemented sophisticated browser hijacking mechanisms, capturing users' browsing data and potentially redirecting them to malicious sites. The malware was introduced through version updates of previously clean extensions, exploiting the auto-update feature of browsers. The campaign demonstrates systemic failures in marketplace security, verification processes, and trust signals, turning productivity tools into surveillance malware. Users are advised to remove affected extensions and monitor their accounts for suspicious activity.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: trust exploitation
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses