VYPR
researchPublished Aug 10, 2026· 1 source

Fake Google Translate Chrome Extension Enables Remote Browser Control and Data Theft

A malicious Chrome extension disguised as Google Translate allows attackers to remotely control browsers, steal sensitive data, and conduct man-in-the-browser phishing attacks.

Cybersecurity researchers have uncovered a sophisticated malicious Chrome extension that impersonates the legitimate Google Translate service, granting attackers extensive remote control over users' browsers. This threat, detailed by VMRay researchers, operates through a multi-stage infection chain that begins with a suspected Rust-based malware loader. This loader deploys a malicious Chrome extension alongside an AutoIt script, which then installs the Stealcv2 information-stealing malware.

Once installed, the fraudulent extension possesses the capability to harvest a wide array of sensitive data stored within the browser. This includes browsing history, saved bookmarks, details of installed extensions, cookies, and stored credentials. This pilfered information can be instrumental for attackers in hijacking online accounts, bypassing session-based security measures, profiling victims, and identifying high-value targets such as email providers, cryptocurrency exchanges, cloud consoles, and corporate applications.

The most alarming feature of this malware is its ability to provide attackers with a real-time view of the victim's Chrome windows and enable remote interaction via mouse clicks and keyboard input. This effectively transforms the user's browser into a remotely controlled interface for the threat actor. The extension leverages Chrome's extension APIs, which, when granted broad permissions, can access sensitive tab properties or inject scripts into websites—capabilities that are easily abused by malicious add-ons.

Unlike typical remote access malware, this campaign is specifically designed to conceal fraudulent activities. The extension reportedly facilitates remote control of browser windows even when they are not in focus, allowing attackers to operate in the background while the victim is engaged with other applications. This stealthy approach significantly reduces the likelihood of a user noticing unauthorized clicks, navigation, or form submissions within their browser.

Further enhancing its malicious capabilities, the malware includes features for configuring proxies and injecting attacker-controlled JavaScript into targeted websites. The proxy configuration can reroute browser traffic through infrastructure controlled by the attackers, while JavaScript injection allows them to alter the content users see or manipulate active sessions on specific domains. This opens avenues for account takeovers, payment fraud, data theft, and targeted social engineering attacks.

A particularly dangerous tactic employed is a man-in-the-browser phishing technique. The extension can overlay a legitimate website with an iframe loaded from an attacker-controlled phishing page. Crucially, the browser's address bar may continue to display the genuine domain, potentially tricking users into believing they are interacting with a legitimate login portal. This could lead victims to submit sensitive information like passwords, multi-factor authentication codes, or payment details directly to criminals.

The use of the Google Translate branding is a strategic choice by threat actors, as translation extensions are common, widely used, and generally perceived as low-risk by users. This tactic echoes previous campaigns, such as one linked to the Kimsuky threat actor, which also used a Chrome extension named 'GoogleTranslate.crx' for data collection. Users are strongly advised to meticulously review their installed Chrome extensions, remove any unfamiliar or unnecessary add-ons, and carefully scrutinize permission requests, especially those seeking broad access to website data.

Organizations should implement policies to restrict unmanaged extensions, monitor for suspicious browser policy changes, and enforce phishing-resistant multi-factor authentication to mitigate the impact of stolen credentials and session data. The identified command-and-control servers and malware hashes provide crucial indicators of compromise for detection and defense.

Synthesized by Vypr AI