{"id":9595,"date":"2026-01-01T10:05:17","date_gmt":"2026-01-01T10:05:17","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/01\/darkspectre-hackers-infected-8-8-million-chrome-edge-and-firefox-users-with-malware\/"},"modified":"2026-01-01T10:05:17","modified_gmt":"2026-01-01T10:05:17","slug":"darkspectre-hackers-infected-8-8-million-chrome-edge-and-firefox-users-with-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/01\/darkspectre-hackers-infected-8-8-million-chrome-edge-and-firefox-users-with-malware\/","title":{"rendered":"DarkSpectre Hackers Infected 8.8 Million Chrome, Edge, and Firefox Users with Malware"},"content":{"rendered":"<p>    DarkSpectre Hackers Infected 8.8 Million Chrome, Edge, and Firefox Users with Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Researchers have uncovered DarkSpectre, a well-funded Chinese threat actor responsible for infecting over 8.8 million users across Chrome, Edge, and Firefox browsers through a series of highly coordinated malware campaigns spanning seven years. <\/p>\n<p>The discovery reveals a level of operational sophistication rarely seen in the threat landscape, with the group running multiple distinct campaigns simultaneously, each targeting different objectives ranging from consumer fraud to corporate espionage.<\/p>\n<p>The operation consists of three major campaigns: ShadyPanda affecting 5.6 million users, the newly discovered <a href=\"https:\/\/cybersecuritynews.com\/zoom-users-beware\/\" target=\"_blank\" rel=\"noreferrer noopener\">Zoom Stealer<\/a> campaign targeting 2.2 million users, and GhostPoster impacting 1.05 million users. <\/p>\n<p>Rather than operating as separate threat actors, investigators confirmed these represent a single, highly organized criminal organization with substantial resources and strategic planning capabilities. <\/p>\n<p>The group demonstrates remarkable patience, maintaining legitimate-appearing browser extensions for five or more years before weaponizing them with malicious payloads.<\/p>\n<p>Koi analysts <a href=\"https:\/\/www.koi.ai\/blog\/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the connection between these campaigns while analyzing infrastructure linked to ShadyPanda. <\/p>\n<p>They discovered that while the group used two legitimate domains\u2014infinitynewtab.com and infinitytab.com\u2014to power actual extension features like weather widgets and new tab pages, these same domains connected to entirely different malicious command-and-control infrastructure. <\/p>\n<p>This clever technique of embedding legitimate functionality alongside hidden <a href=\"https:\/\/cybersecuritynews.com\/asus-embedded-malicious-code-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious code<\/a> became the thread linking all three operations together.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi10iQLhnKUzMBwj8sSNVzu2tSzw8fWmXgVoDJLNYkkFdkSaVPNdVn7blbEn24fEBqxWmk9rPWqOzdNayyK2y3mEP7MxpmEHFBUEQJzlLZ8YUQe51791OC94-K-qR5iYUoFbrWRylFQryzwHqOTSogxVn5bKtZKIjG1M1XMv5bFOphKS5Aj89bCs3N_vWA\/s16000\/Dark%2520Spectre%2520%28Source%2520-%2520Koi%29.webp?ssl=1\" alt=\"Dark Spectre (Source - Koi)\"><figcaption class=\"wp-element-caption\">Dark Spectre (Source \u2013 Koi)<\/figcaption><\/figure>\n<\/div>\n<p>The discovery process resembled following a complex web. One domain led to extensions, which revealed new domains, which connected to additional extensions operated by publishers with dozens of other malicious tools. <\/p>\n<p>The expansion eventually uncovered over 100 connected extensions across multiple browser marketplaces. <\/p>\n<p>As researchers investigated further, they noticed that certain newly discovered extensions communicated with domains already flagged in previous investigations, confirming that ShadyPanda, GhostPoster, and Zoom Stealer represented a single actor operating at nation-state scale.<\/p>\n<h2 class=\"wp-block-heading\" id=\"time-bomb-activation-and-evasion-tactics\"><strong>Time-Bomb Activation and Evasion Tactics<\/strong><\/h2>\n<p>The most alarming aspect of DarkSpectre\u2019s methodology lies in their sophisticated persistence and detection-evasion techniques. <\/p>\n<p>The group employs what researchers term \u201ctime-bomb\u201d extensions\u2014malicious tools that remain dormant for extended periods before activating their payload. <\/p>\n<p>One extension called \u201cNew Tab \u2013 Customized Dashboard\u201d demonstrates this approach by waiting three days after installation before connecting to command-and-control servers to download its actual malicious code.<\/p>\n<p>During the review process when marketplaces evaluate extensions for safety, this extension appears completely legitimate. Browser reviewers cannot detect the malicious behavior because it simply does not activate during testing. <\/p>\n<p>The extension only begins its malicious activities after passing all <a href=\"https:\/\/cybersecuritynews.com\/genai-security-explained-key-risks-and-how-to-mitigate-them\/\" target=\"_blank\" rel=\"noreferrer noopener\">security checks<\/a> and reaching a real user\u2019s browser. <\/p>\n<p>To further evade detection, the malware only activates on approximately ten percent of page loads, making it exponentially harder to identify during routine testing or analysis.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhEvkm4nhaRESOY2Qe_96_S9BQONHgvk_cysl7VktSqMwzstix4do4qJaqsp17mEoTzLF9Zbki23AWozQ_9vbNXjSl3edicRhZ9la9owNlPrWdJzzw7AMdBy0rTbssAtrg9DZ-v4l7OCfdvGzsnjNM4BQ7VL_luI1ivDyY0Ocoa0WFcepgINkz90wnRgJQ\/s16000\/Chrome%2520Audio%2520Capture%2520live%2520in%2520the%2520marketplace%2520%28Source%2520-%2520Koi%29.webp?ssl=1\" alt=\"Chrome Audio Capture live in the marketplace (Source - Koi)\"><figcaption class=\"wp-element-caption\">Chrome Audio Capture live in the marketplace (Source \u2013 Koi)<\/figcaption><\/figure>\n<\/div>\n<p>The payload delivery itself showcases advanced <a href=\"https:\/\/cybersecuritynews.com\/malware-obfuscation\/\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscation<\/a> techniques. DarkSpectre disguises malicious code as PNG image files, a method known as steganography. <\/p>\n<p>The extension loads its own logo, extracts the hidden JavaScript code embedded within the image file, and executes it silently in the background. <\/p>\n<p>The JavaScript is wrapped in multiple layers of protection including custom encoding, XOR encryption, and packed code designed specifically to defeat automated <a href=\"https:\/\/cybersecuritynews.com\/how-intrusion-detection-and-prevention-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">detection tools<\/a>. <\/p>\n<p>Once activated, the extension downloads approximately sixty-seven kilobytes of additional encoded JavaScript from the operators\u2019 servers, giving the threat actors complete control over what executes in the user\u2019s browser without requiring an extension update that would again trigger the review process.<\/p>\n<p>This configuration-based approach represents the true innovation in DarkSpectre\u2019s operation. Instead of pushing updates to change functionality\u2014which would alert reviewers and users\u2014the operators simply modify what their servers return when extensions phone home. <\/p>\n<p>Defenders cannot combat the threat by blocking a single malicious update because the threat actor changes the payload on their backend servers dynamically, maintaining complete operational flexibility.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/darkspectre-hackers-infected-8-8-million-chrome-users\/\">DarkSpectre Hackers Infected 8.8 Million Chrome, Edge, and Firefox Users with Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/darkspectre-hackers-infected-8-8-million-chrome-users\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>DarkSpectre Hackers Infected 8.8 Million Chrome, Edge, and Firefox Users with Malware Researchers have uncovered DarkSpectre, a well-funded Chinese threat actor responsible for infecting over 8.8 million users across Chrome, Edge, and Firefox browsers through a series of highly coordinated malware campaigns spanning seven years. The discovery reveals a level of operational sophistication rarely seen [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9595","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9595"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9595"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9595\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9595"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9595"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9595"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}