Almost 7 million users have attempted to install malicious browser extensions since 2020, with 70% of those extensions used as adware to target users with advertisements. Kaspersky reported that users attempted over 13,00,000 times to install malicious extensions throughout H1 '22, an increase compared to last year's figures.
The most common payloads carried by malicious web browser extensions during the first half of 2022 belonged to adware families, snooping on browsing activity and promoting affiliate links.
From January 2020 to June 2022, Kaspersky recorded adware extensions targeting 4.3 million unique users, corresponding to roughly 70% of all malicious extensions in that period. This stat reflects how large of an adware delivery funnel malicious extensions are, compared to any other delivery mechanism.
The most common malware hiding in the browser extension scripts is ‘WebSearch’, targeting 876,924 users this year, typically mimicking productivity tools such as DOC to PDF converters and document merging utilities. WebSearch monitors users’ browsing activity to profile them based on their interests and then promotes links from affiliate marketing programs that help monetize the infection.
The second most common adware is ‘AddScript’, seen in attacks against 156,698 unique users. AddScript runs covertly in the background while the extensions that carry it offer the promised functionality, i.e., downloading videos from the web.
The third-most popular adware is ‘DealPly’, responsible for 97,525 infection attempts in the first half of the year. This adware begins with the execution of pirated software like KMS activators and game cheat engines downloaded from peer-to-peer networks and shady sites.
Users are advised to only download extensions from the browser’s official web store, examine user comments and reviews, and run a background check on the developer/publisher. Try to use the least amount of extensions and periodically review the installed add-ons.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.



