Find notable cyber news and cases, enriched with sources, timelines, and signals.

Commercial adware and traffic-attribution-fraud affiliate operation using Chrome extensions

Threat Actor Meta
First reported
Last updated
Happening score
H score 20
1 unique sources, 1 articles

Summary

Hide ▲

Researchers found a commercial adware and traffic-attribution-fraud affiliate operation abusing Chrome extensions to fabricate traffic signals and monetize installs, increasing fraud-enablement risk across the extension ecosystem. The network spans 38 publisher accounts, three brand backends, and 105,000 installs, showing coordinated distribution at meaningful scale.

Related Happenings

ModHeader browser extension hidden browsing-history collector

Malware Activity
H score42 First: 13.07.2026 20:17 Last: 13.07.2026 20:17 Sources 1

About this happening: The ModHeader browser extension shipped a hidden browsing-history collector in its official store version, exposing about 1.6 million installs to covert domain and...

Chrome extension PUP distribution network with fake organic traffic

Malware Activity
H score18 First: 15.06.2026 14:07 Last: 15.06.2026 14:07 Sources 1

How related: Cybersecurity researchers have discovered a network of 152 Google Chrome extensions that act as new tab live wallpaper add-ons to distribute a potentially unwanted program (PUP) family.

About this happening: A network of 152 Google Chrome extensions is distributing a potentially unwanted program (PUP) family through new-tab live-wallpaper add-ons, creating a broad browser-base...

Trapdoor Android malvertising and ad-fraud campaign

Campaign
H score39 First: 19.05.2026 19:38 Last: 19.05.2026 19:38 Sources 1

About this happening: The Trapdoor campaign is a self-sustaining malvertising and ad-fraud operation targeting Android users and turning app installs into revenue through threat-actor-contr...

Chrome Web Store malicious extensions coordinated campaign using shared C2

Campaign
H score38 First: 14.04.2026 23:33 Last: 14.04.2026 23:33 Sources 1

About this happening: A coordinated Chrome Web Store extension operation is stealing Google OAuth2 Bearer tokens, deploying backdoors, and running ad fraud across more than 100 malici...

108 Malicious Google Chrome extensions sharing a C2 backend

Malware Activity
H score11 First: 14.04.2026 11:35 Last: 14.04.2026 11:35 Sources 1

About this happening: 108 malicious Google Chrome extensions were found to use the same C2 infrastructure to steal credentials, sessions, and browsing data while injecting ads and arbitrary Jav...

Timeline

  1. 15.06.2026 14:07 2 articles · 1mo ago

    Researchers uncover 152 Chrome wallpaper extensions tied to adware and fake traffic

    Initial Disclosure

    Researchers uncovered 152 Google Chrome extensions posing as live-wallpaper new-tab add-ons and linked them to a financially motivated commercial adware and traffic-attribution-fraud affiliate operation. The cluster spans 38 Chrome Web Store publisher accounts and three brand backends, with 105,000 installs, and the listings' privacy policies admit logging IP addresses, ISP, click counts, and referrers while sharing that data with Google AdSense, DoubleClick, and third-party ad partners. Some extensions also use hard-coded install and uninstall URLs in js/bg.js to disguise self-opened tabs as organic Google traffic and to make uninstall activity look like genuine Google Search clicks.

    Show sources