Fake Firefox Extension Hijacks Google Accounts Without Stealing Passwords First

A malicious Firefox extension masquerading as a PDF identity-verification utility has been found targeting Google accounts through session-cookie theft and automated account-takeover activity. The campaign is notable because the add-on initially contains no obvious credential-stealing code, malicious URLs, or hardcoded payloads, allowing it to appear benign during basic static analysis. Malicious functionality was introduced in […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: