Skip to content
Every technique
T1176.001Detection written

Browser Extensions

PersistenceLinux, Windows, macOS

Where this stands

One published detection covers this technique. Every one is unverified — no rule on Siemphony has been executed against real telemetry.

What the technique is

Adversaries may abuse internet browser extensions to establish persistent access to victim systems. Browser extensions or plugins are small programs that can add functionality to and customize aspects of internet browsers. They can be installed directly via a local file or custom URL or through a browser's app store - an official online platform where users can browse, install, and manage extensions for a specific web browser. Extensions generally inherit the web browser's permissions previously granted. Malicious extensions can be installed into a browser through malicious app store downloads masquerading as legitimate extensions, through social engineering, or by an adversary that has already compromised a system. Security can be limited on browser app stores, so it may not be difficult for malicious extensions to defeat automated scanners. Depending on the browser, adversaries may also manipulate an extension's update url to install updates from an adversary-controlled server or manipulate the mobile configuration file to silently install additional extensions. Adversaries may abuse how chromium-based browsers load extensions by modifying or replacing the Preferences and/or Secure Preferences files to silently install malicious extensions. […]

Read it on attack.mitre.org

What MITRE says you would watch

  • AN0123

    Installation of a new browser extension followed by suspicious file writes or outbound network connections to untrusted domains by the browser process.

  • AN0124

    Installation of malicious.mobileconfig profiles or browser extension plist entries followed by abnormal browser child process activity.

  • AN0125

    Manual or scripted installation of Chrome extensions using user scripts or config files, followed by unexpected network connections from browser processes.

Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.