databycloud1104 is the publisher name associated with a coordinated campaign of malicious Google Chrome extensions targeting enterprise users of major HR and finance platforms, including Workday, NetSuite, and SuccessFactors. Four extensions were published under the databycloud1104 name, while a closely related fifth extension operated under the branding softwareaccess and shared the same infrastructure patterns and attack mechanisms. The operation masqueraded as legitimate productivity tooling intended to simplify multi-account access, but its hidden functionality enabled theft of authentication material and subsequent account takeover. The campaign’s core tradecraft centered on session hijacking through theft of authentication tokens and cookies, including repeated extraction of session material to keep stolen access current. At least one related extension implemented bidirectional cookie injection, allowing attackers to import stolen session cookies into their own browsers and access victim accounts without needing passwords, including bypass of multi-factor authentication protections tied to the original login flow. This indicates a mature focus on post-authentication compromise rather than simple credential phishing alone. A notable feature of the operation was active interference with incident response and account recovery. The extensions used DOM manipulation and high-frequency MutationObserver-based monitoring to detect when users or administrators opened sensitive security and administration pages, then blanked content or redirected the browser to disrupt remediation. Reported blocked functions included password resets, account deactivation, MFA device management, and access to security audit logs. This defensive suppression behavior could prevent standard containment actions and prolong unauthorized access, in some cases forcing organizations to migrate affected users to new accounts. The campaign affected more than 2,300 users across enterprise environments. Based on the observed behavior, databycloud1104 demonstrated capabilities spanning initial access through malicious browser extensions, credential and session theft, persistence through repeated token harvesting, post-exploitation via account takeover, and defense evasion by obstructing administrative security workflows. The available information supports a financially or operationally motivated cybercrime operation, but a definitive attribution to a specific country or state sponsor is not currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.