Skip to main content
  1. Home
  2. Computing
  3. News

This Chrome extension lets hackers remotely seize your PC

Add as a preferred source on Google

Malicious extensions on Google Chrome are being used by hackers remotely in an effort to steal sensitive information.

As reported by Bleeping Computer, a new Chrome browser botnet titled ‘Cloud9’ is also capable of logging keystrokes, as well as distributing ads and malicious code.

A depiction of a hacker breaking into a system via the use of code.
Getty Images

The browser botnet operates as a remote access trojan (RAT) for the Chromium web browser, which includes both Chrome and Microsoft Edge. As such, it’s not just login credentials that can be accessed; hackers can also launch distributed denial of service (DDoS) attacks.

Recommended Videos

The Chrome extension in question is naturally not accessible via Google’s official Chrome web store, so you may be wondering how victims are being targeted. Websites that exist to spread infections via bogus Adobe Flash Player update notifications are being used instead.

Security researchers at Zimperium have confirmed that Cloud9 infection rates have been detected in multiple regions around the world.

The foundation of Cloud9 is three central JavaScript files that can obtain information of the target system, and mine cryptocurrency on that same PC in addition to injecting scripts in order to launch browser exploits.

Multiple vulnerabilities are being exploited, Zimperium notes, including CVE-2019-11708 and CVE-2019-9810 in Firefox, CVE-2014-6332 and CVE-2016-0189 for Internet Explorer, and CVE-2016-7200 for Microsoft Edge.

Although the vulnerabilities are commonly used to install Windows malware, the Cloud9 extension can steal cookies from a browser, allowing hackers to take over valid user sessions.

Furthermore, the malware comes with a keylogger — software that can essentially send all your key presses to the attackers. A “clipper” module was also discovered in the extension, which allows the PC to access copied passwords or credit cards.

“Layer 7 attacks are usually very hard to detect because the TCP connection looks very similar to legitimate requests,” Zimperium stated. “The developer is likely using this botnet to provide a service to perform DDOS.”

Another way the threat actors behind Cloud9 generate even more illicit income is by injecting advertisements and then loading these webpages in the background to accrue ad impressions.

With Cloud9 being spotted on cybercrime forums, the operators could be selling its malicious extension to interested parties. With this in mind, always double-check if you’re installing anything on your browser from an unofficial source and enable two-factor authentication where possible.

Zak Islam
Former Contributor
Zak covers the latest news in the technology world, particularly the computing field. A fan of anything pertaining to tech…
How to change the default apps on a Mac
Apple's default apps are great, until they're not. Here's how to swap them out in seconds.
change default apps on Mac featured image

One of my favorite things about macOS is that it comes with default apps to handle your everyday tasks. You get Safari to browse the web, the Mail app to handle your emails, and the Preview app to open and view photos and PDFs.

But what if you want to use a third-party app you prefer over the default app? Thankfully, Apple makes it easy to change the default apps on your Mac. So, whether you want to use Google Chrome or Outlook, here’s how you can set them as the default on your Mac. 

Read more
You can now choose how hard Claude thinks before answering your queries
For the first time, Claude users can decide whether their AI assistant thinks fast or thinks deep.
Page, Text, Business Card

Anthropic just released Claude Opus 4.8, and while the benchmark improvements are quite real, the most meaningful change for everyday users is something far simpler. 

You can now tell Claude how hard to think before it responds to your query. Along with that, dynamic workflows are now available in research preview for Enterprise, Team, and Max plan users. 

Read more
Copilot gets a redesign and it now wants to do more without being an eyesore
Microslop Microsoft AI Copilot logo

Microsoft is giving Copilot a quiet but meaningful redesign, and this time the focus is not just on making it more powerful. It is about making it feel like something that naturally belongs in your workflow.

Across Microsoft 365, Copilot is being reshaped to reduce visual noise and increase usefulness. Instead of constantly demanding attention, it is being designed to sit in the background when needed and step forward only when it actually helps. That shift might sound subtle, but in day-to-day work, it changes how often you feel interrupted versus supported.

Read more