Browser Extensions Used for Chromium C2 Persistence and Cookie Theft
SpecterOps research reveals how browser extensions can be leveraged to turn Chromium into a persistent command and control (C2) platform. This method allows for silent installation of extensions, enabling continuous cookie theft and browser takeover. The technique builds on previous research into Chromium’s Application Mode, highlighting a significant threat to authenticated browser sessions.