LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1176.001: Browser Extensions

MITRE ATT&CK T1176.001: Browser Extensions Technique details for Linux, Windows, macOS, with detection guidance, relationships and mapped CVEs.

EnterpriseT1176.001Sub-techniqueObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Browser extensions are a persistence risk because they live inside a tool employees use constantly: the web browser. A malicious or manipulated extension can survive browser sessions, inherit browser-granted permissions, observe user-entered data such as credentials, change browser settings, and in some cases support command-and-control or installation of other malware. For leaders, the practical issue is whether the organization can prove which extensions are installed, who approved them, and whether browser configuration changes are being monitored across Windows, macOS, and Linux endpoints.

Executive priority

Prioritize this where browser-based access is central to business operations, identity use, SaaS administration, banking, or sensitive web workflows. The control question is not only “are endpoints protected?” but “do we govern browser extensions like software?” This technique supports persistence and has relationships to multiple malware families and a group in ATT&CK, so it is material for incident scoping, credential-risk decisions, compliance evidence around software control, and auditability of endpoint configuration.

Technical view

SOC and detection teams should validate coverage for unauthorized extension installation, suspicious extension permission changes, modified browser Preferences or Secure Preferences files, altered extension update URLs, and macOS configuration-profile activity involving .mobileconfig files where applicable. Because MITRE provides no official detection text for this object, teams should use the related detection strategy DET0044, “Detecting Malicious Browser Extensions Across Platforms,” as the ATT&CK-linked starting point and then test against local browser deployment patterns. Incident responders should include browser extension inventory, browser configuration files, and extension directories in host triage for Windows, macOS, and Linux systems.

Likely telemetry

  • Browser extension inventory and version data across managed endpoints
  • Browser configuration files, including Preferences and Secure Preferences where available
  • File creation, modification, or replacement events in browser extension storage locations
  • Extension permission, privacy, security-control, and update URL changes
  • macOS configuration profile and .mobileconfig installation-related events where applicable

Detection direction

  • Establish an approved-extension baseline by browser, platform, user role, and business need, then alert on unapproved additions or unexpected permission expansion.
  • Tune detections to separate legitimate enterprise-managed extension deployment from silent local installation, app-store masquerading, or configuration-file manipulation.
  • Monitor for changes to browser Preferences/Secure Preferences files when the browser is not running, since ATT&CK notes this can be abused to silently load extensions.
  • Review extension update URLs and sources for deviation from expected trusted stores or approved internal deployment paths.
  • For macOS, account for the ATT&CK distinction that pre-macOS 11 command-line profile installation behavior differs from macOS 11+ user-interaction requirements.

Mitigation priorities

  • Implement auditing first: maintain evidence of installed extensions, permissions, update sources, and browser configuration changes.
  • Limit software installation by restricting who can install extensions and by using approved-extension allowlists or equivalent managed browser controls where available.
  • Apply execution-prevention and application-control principles to reduce unauthorized code and installer activity that may introduce malicious extensions.
  • Keep browsers, operating systems, and managed endpoint components updated to reduce exposure to known browser and platform weaknesses.
  • Use user training to reduce social-engineering-driven extension installation and to encourage reporting of unexpected browser changes or extension prompts.
Additional notes and limits

This object is a sub-technique of Software Extensions and is scoped to the persistence tactic on Linux, Windows, and macOS. ATT&CK relationships show use by Kimsuky and several software entries, including macOS adware/Trojans, Windows banking trojans, stealers, and a Chrome-extension-themed malware entry. Treat those relationships as ATT&CK context for defensive prioritization, not as proof of current activity in any specific environment.

MITRE did not provide official detection text for this technique in the supplied object. Specific file paths, browser-management mechanisms, and event IDs vary by browser, operating system, and enterprise management stack, so local validation is required before claiming coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Browser Extensions

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1176Software ExtensionsThis object subtechnique of Software Extensions.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0094: Kimsuky

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.[1][2][3][4][5][6]

Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).[7][8][9] In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.[10]

DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

MalwareEnterprise

S1122: Mispadu

Mispadu is a banking trojan written in Delphi that was first observed in 2019 and uses a Malware-as-a-Service (MaaS) business model.[1][2] This malware is operated, managed, and sold by the Malteiro cybercriminal group.[2] Mispadu has mainly been used to target victims in Brazil and Mexico, and has also had confirmed operations throughout Latin America and Europe.[2][3][4]

Windows
MalwareEnterprise

S1201: TRANSLATEXT

TRANSLATEXT is malware that is believed to be used by Kimsuky.[1] TRANSLATEXT masqueraded as a Google Translate extension for Google Chrome, but is actually a collection of four malicious Javascript files that perform defense evasion, information collection and exfiltration.[1]

Windows
MalwareEnterprise

S0531: Grandoreiro

Grandoreiro is a banking trojan written in Delphi that was first observed in 2016 and uses a Malware-as-a-Service (MaaS) business model. Grandoreiro has confirmed victims in Brazil, Mexico, Portugal, and Spain.[1][2]

Windows
MalwareEnterprise

S0482: Bundlore

Bundlore is adware written for macOS that has been in use since at least 2015. Though categorized as adware, Bundlore has many features associated with more traditional backdoors.[1]

macOS
Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
8e60b0ecf658babf...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle8e60b0ecf658…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Wikipedia Browser Extension

    Wikipedia. (2017, October 8). Browser Extension. Retrieved January 11, 2018.

    Open source URL
  2. [2]
    Chrome Extensions Definition

    Chrome. (n.d.). What are Extensions?. Retrieved November 16, 2017.

    Open source URL
  3. [3]
    Malicious Chrome Extension Numbers

    Jagpal, N., et al. (2015, August). Trends and Lessons from Three Years Fighting Malicious Extensions. Retrieved November 17, 2017.

    Open source URL
  4. [4]
    Pulsedive

    Pulsedive Threat Research. (2025, March 21). Rilide - An Information Stealing Browser Extension. Retrieved September 22, 2025.

    Open source URL
  5. [5]
    xorrior chrome extensions macOS

    Chris Ross. (2019, February 8). No Place Like Chrome. Retrieved April 27, 2021.

    Open source URL
  6. [6]
    Chrome Extension Crypto Miner

    Brinkmann, M. (2017, September 19). First Chrome extension with JavaScript Crypto Miner detected. Retrieved November 16, 2017.

    Open source URL
  7. [7]
    ICEBRG Chrome Extensions

    De Tore, M., Warner, J. (2018, January 15). MALICIOUS CHROME EXTENSIONS ENABLE CRIMINALS TO IMPACT OVER HALF A MILLION USERS AND GLOBAL BUSINESSES. Retrieved January 17, 2018.

    Open source URL
  8. [8]
    Banker Google Chrome Extension Steals Creds

    Marinho, R. (n.d.). (Banker(GoogleChromeExtension)).targeting. Retrieved November 18, 2017.

    Open source URL
  9. [9]
    Catch All Chrome Extension

    Marinho, R. (n.d.). "Catch-All" Google Chrome Malicious Extension Steals All Posted Data. Retrieved November 16, 2017.

    Open source URL
  10. [10]
    Stantinko Botnet

    Vachon, F., Faou, M. (2017, July 20). Stantinko: A massive adware campaign operating covertly since 2012. Retrieved November 16, 2017.

    Open source URL
  11. [11]
    Chrome Extension C2 Malware

    Kjaer, M. (2016, July 18). Malware in the browser: how you might get hacked by a Chrome extension. Retrieved September 12, 2024.

    Open source URL
  12. [12]
    Browers FriarFox

    Raggi, Michael. Proofpoint Threat Research Team. (2021, February 25). TA413 Leverages New FriarFox Browser Extension to Target the Gmail Accounts of Global Tibetan Organizations. Retrieved November 17, 2024.

    Open source URL
  13. [13]
    Browser Adrozek

    Microsoft Threat Intelligence. (2020, December 10). Widespread malware campaign seeks to silently inject ads into search results, affects multiple browsers. Retrieved February 26, 2024.

    Open source URL
  14. [14]
    ESET Security Mispadu Facebook Ads 2019

    ESET Security. (2019, November 19). Mispadu: Advertisement for a discounted Unhappy Meal. Retrieved March 13, 2024.

    Open source URL
  15. [15]
    Zdnet Kimsuky Dec 2018

    Cimpanu, C.. (2018, December 5). Cyber-espionage group uses Chrome extension to infect victims. Retrieved August 26, 2019.

    Open source URL
  16. [16]
    Netscout Stolen Pencil Dec 2018

    ASERT team. (2018, December 5). STOLEN PENCIL Campaign Targets Academia. Retrieved February 5, 2019.

    Open source URL
  17. [17]
    Intego Shlayer Apr 2018

    Vrijenhoek, Jay. (2018, April 24). New OSX/Shlayer Malware Variant Found Using a Dirty New Trick. Retrieved September 6, 2019.

    Open source URL
  18. [18]
    Malwarebytes Crossrider Apr 2018

    Reed, Thomas. (2018, April 24). New Crossrider variant installs configuration profiles on Macs. Retrieved September 6, 2019.

    Open source URL
  19. [19]
    Cybereason LumaStealer Undated

    Cybereaon Security Services Team. (n.d.). Your Data Is Under New Lummanagement: The Rise of LummaStealer. Retrieved March 22, 2025.

    Open source URL
  20. [20]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  21. [21]
    IBM Grandoreiro April 2020

    Abramov, D. (2020, April 13). Grandoreiro Malware Now Targeting Banks in Spain. Retrieved November 12, 2020.

    Open source URL
  22. [22]
    MacKeeper Bundlore Apr 2019

    Sushko, O. (2019, April 17). macOS Bundlore: Mac Virus Bypassing macOS Security Features. Retrieved June 30, 2020.

    Open source URL
  23. [23]
    Technospot Chrome Extensions GP

    Mohta, A. (n.d.). Block Chrome Extensions using Google Chrome Group Policy Settings. Retrieved January 10, 2018.

  24. [24]
    Banker Google Chrome Extension Steals Creds

    Marinho, R. (n.d.). (Banker(GoogleChromeExtension)).targeting. Retrieved November 18, 2017.

    Open source URL
  25. [25]
    Banker Google Chrome Extension Steals Creds

    Marinho, R. (n.d.). (Banker(GoogleChromeExtension)).targeting. Retrieved November 18, 2017.

    Open source URL
  26. [26]
    Browers FriarFox

    Raggi, Michael. Proofpoint Threat Research Team. (2021, February 25). TA413 Leverages New FriarFox Browser Extension to Target the Gmail Accounts of Global Tibetan Organizations. Retrieved November 17, 2024.

    Open source URL
  27. [27]
    Browers FriarFox

    Raggi, Michael. Proofpoint Threat Research Team. (2021, February 25). TA413 Leverages New FriarFox Browser Extension to Target the Gmail Accounts of Global Tibetan Organizations. Retrieved November 17, 2024.

    Open source URL
  28. [28]
    Browser Adrozek

    Microsoft Threat Intelligence. (2020, December 10). Widespread malware campaign seeks to silently inject ads into search results, affects multiple browsers. Retrieved February 26, 2024.

    Open source URL
  29. [29]
    Browser Adrozek

    Microsoft Threat Intelligence. (2020, December 10). Widespread malware campaign seeks to silently inject ads into search results, affects multiple browsers. Retrieved February 26, 2024.

    Open source URL
  30. [30]
    Catch All Chrome Extension

    Marinho, R. (n.d.). "Catch-All" Google Chrome Malicious Extension Steals All Posted Data. Retrieved November 16, 2017.

    Open source URL
  31. [31]
    Catch All Chrome Extension

    Marinho, R. (n.d.). "Catch-All" Google Chrome Malicious Extension Steals All Posted Data. Retrieved November 16, 2017.

    Open source URL
  32. [32]
    Chrome Extension C2 Malware

    Kjaer, M. (2016, July 18). Malware in the browser: how you might get hacked by a Chrome extension. Retrieved September 12, 2024.

    Open source URL
  33. [33]
    Chrome Extension C2 Malware

    Kjaer, M. (2016, July 18). Malware in the browser: how you might get hacked by a Chrome extension. Retrieved September 12, 2024.

    Open source URL
  34. [34]
    Chrome Extension Crypto Miner

    Brinkmann, M. (2017, September 19). First Chrome extension with JavaScript Crypto Miner detected. Retrieved November 16, 2017.

    Open source URL
  35. [35]
    Chrome Extension Crypto Miner

    Brinkmann, M. (2017, September 19). First Chrome extension with JavaScript Crypto Miner detected. Retrieved November 16, 2017.

    Open source URL
  36. [36]
    Chrome Extensions Definition

    Chrome. (n.d.). What are Extensions?. Retrieved November 16, 2017.

    Open source URL
  37. [37]
    Chrome Extensions Definition

    Chrome. (n.d.). What are Extensions?. Retrieved November 16, 2017.

    Open source URL
  38. [38]
    ICEBRG Chrome Extensions

    De Tore, M., Warner, J. (2018, January 15). MALICIOUS CHROME EXTENSIONS ENABLE CRIMINALS TO IMPACT OVER HALF A MILLION USERS AND GLOBAL BUSINESSES. Retrieved January 17, 2018.

    Open source URL
  39. [39]
    ICEBRG Chrome Extensions

    De Tore, M., Warner, J. (2018, January 15). MALICIOUS CHROME EXTENSIONS ENABLE CRIMINALS TO IMPACT OVER HALF A MILLION USERS AND GLOBAL BUSINESSES. Retrieved January 17, 2018.

    Open source URL
  40. [40]
    Malicious Chrome Extension Numbers

    Jagpal, N., et al. (2015, August). Trends and Lessons from Three Years Fighting Malicious Extensions. Retrieved November 17, 2017.

    Open source URL
  41. [41]
    Malicious Chrome Extension Numbers

    Jagpal, N., et al. (2015, August). Trends and Lessons from Three Years Fighting Malicious Extensions. Retrieved November 17, 2017.

    Open source URL
  42. [42]
    Pulsedive

    Pulsedive Threat Research. (2025, March 21). Rilide - An Information Stealing Browser Extension. Retrieved September 22, 2025.

    Open source URL
  43. [43]
    Pulsedive

    Pulsedive Threat Research. (2025, March 21). Rilide - An Information Stealing Browser Extension. Retrieved September 22, 2025.

    Open source URL
  44. [44]
    Stantinko Botnet

    Vachon, F., Faou, M. (2017, July 20). Stantinko: A massive adware campaign operating covertly since 2012. Retrieved November 16, 2017.

    Open source URL
  45. [45]
    Stantinko Botnet

    Vachon, F., Faou, M. (2017, July 20). Stantinko: A massive adware campaign operating covertly since 2012. Retrieved November 16, 2017.

    Open source URL
  46. [46]
    Wikipedia Browser Extension

    Wikipedia. (2017, October 8). Browser Extension. Retrieved January 11, 2018.

    Open source URL
  47. [47]
    Wikipedia Browser Extension

    Wikipedia. (2017, October 8). Browser Extension. Retrieved January 11, 2018.

    Open source URL
  48. [48]
    mitre-attackT1176.001
    Open source URL
  49. [49]
    mitre-attackT1176.001
    Open source URL
  50. [50]
    mitre-attackT1176.001
    Open source URL
  51. [51]
    xorrior chrome extensions macOS

    Chris Ross. (2019, February 8). No Place Like Chrome. Retrieved April 27, 2021.

    Open source URL
  52. [52]
    xorrior chrome extensions macOS

    Chris Ross. (2019, February 8). No Place Like Chrome. Retrieved April 27, 2021.

    Open source URL
  53. [53]
    ESET Security Mispadu Facebook Ads 2019

    ESET Security. (2019, November 19). Mispadu: Advertisement for a discounted Unhappy Meal. Retrieved March 13, 2024.

    Open source URL
  54. [54]
    Netscout Stolen Pencil Dec 2018

    ASERT team. (2018, December 5). STOLEN PENCIL Campaign Targets Academia. Retrieved February 5, 2019.

    Open source URL
  55. [55]
    Zdnet Kimsuky Dec 2018

    Cimpanu, C.. (2018, December 5). Cyber-espionage group uses Chrome extension to infect victims. Retrieved August 26, 2019.

    Open source URL
  56. [56]
    Intego Shlayer Apr 2018

    Vrijenhoek, Jay. (2018, April 24). New OSX/Shlayer Malware Variant Found Using a Dirty New Trick. Retrieved September 6, 2019.

    Open source URL
  57. [57]
    Malwarebytes Crossrider Apr 2018

    Reed, Thomas. (2018, April 24). New Crossrider variant installs configuration profiles on Macs. Retrieved September 6, 2019.

    Open source URL
  58. [58]
    Cybereason LumaStealer Undated

    Cybereaon Security Services Team. (n.d.). Your Data Is Under New Lummanagement: The Rise of LummaStealer. Retrieved March 22, 2025.

    Open source URL
  59. [59]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  60. [60]
    IBM Grandoreiro April 2020

    Abramov, D. (2020, April 13). Grandoreiro Malware Now Targeting Banks in Spain. Retrieved November 12, 2020.

    Open source URL
  61. [61]
    MacKeeper Bundlore Apr 2019

    Sushko, O. (2019, April 17). macOS Bundlore: Mac Virus Bypassing macOS Security Features. Retrieved June 30, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.