GhostPoster is a browser-extension malware campaign that provides persistent attacker-controlled access to browsers and monetizes compromised browsing activity through affiliate-link hijacking, tracking injection, and advertising and click fraud. Initially identified in Firefox extensions, related activity spans Microsoft Edge, Google Chrome, and Opera. It is associated with the Chinese-linked threat actor DarkSpectre. Malicious extensions distributed through official browser marketplaces masquerade as utilities such as VPNs, translators, weather tools, and ad blockers.
GhostPoster conceals JavaScript execution logic inside PNG extension icons using steganography. The extensions extract this code at runtime and use it to retrieve additional obfuscated and encrypted JavaScript from command-and-control servers. Payload decoding incorporates the extension’s runtime identifier, and decrypted code executes in browser memory. Delayed activation, randomized execution delays, and infrequent payload retrieval help evade marketplace reviews, static inspection, and dynamic analysis.
Active payloads support remote code execution within the browser context, inject tracking scripts, redirect traffic for affiliate fraud, and use invisible iframes for advertising and click fraud. They also strip HTTP security headers, including Content-Security-Policy, and bypass CAPTCHA protections. Installed extensions can continue operating after removal from their marketplaces unless they are uninstalled from affected browsers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“LayerX said it found a new cluster of 17 extensions related to GhostPoster impacting Google Chrome and Microsoft Edge.”
3 distinct techniques documented for this family, organized by ATT&CK tactic.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious Firefox extension campaign using steganography in a PNG icon to deliver payloads and evade review/static analysis; associated extensions reached ~840k downloads and persisted up to 5 years.
Malicious browser-extension cluster used to hijack affiliate links, inject tracking code, and conduct click/ad fraud across major browsers.
A malicious browser-extension campaign distributing trojanized extensions via official browser stores. Uses steganography to hide payloads in PNG files, delays execution to evade review/scanning, contacts attacker-controlled servers to fetch additional scripts, and performs credential/personal-data theft, affiliate-link hijacking, tracking-script injection, and HTTP header manipulation to weaken security protections.
A malicious browser extension campaign that concealed malicious code inside seemingly benign PNG image files to evade detection, leveraging shared backend infrastructure across multiple add-ons and focusing on stealth/persistence across Edge, then Chrome and Firefox.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.