$ techbeacon▋
Phishing

Malicious Firefox Add‑On Poses as PDF Verifier to Hijack Google Sessions

Malicious Firefox Add‑On Poses as PDF Verifier to Hijack Google Sessions

Security researchers have identified a rogue Firefox extension that masquerades as a PDF identity‑verification tool but silently siphons Google session cookies, enabling automated takeover of user accounts without ever capturing passwords.

The add‑on appears benign during installation, presenting a familiar interface for handling PDF documents. Once active, it injects scripts that monitor traffic to Google domains, harvests authentication cookies stored by the browser, and forwards them to a command‑and‑control server. The stolen cookies are then used to impersonate the victim and gain full access to Gmail, Drive, and other services.

This technique differs from classic credential‑theft malware that relies on keyloggers or phishing for passwords. By exploiting the browser’s own authentication tokens, the attackers bypass many traditional detection methods, making the threat especially insidious for users who assume their passwords remain safe.

Firefox’s extension ecosystem has long been praised for its flexibility, yet it also presents a vector for abuse. While Mozilla conducts automated and manual reviews, malicious actors continue to craft extensions that blend legitimate functionality with hidden payloads. The Google account ecosystem remains a prized target because of its integration with a wide array of third‑party services and the valuable personal data it contains.

Following the discovery, Mozilla promptly removed the offending add‑on from its repository and issued a notice urging users to uninstall any copies already present on their systems. Security experts recommend enabling two‑factor authentication on Google accounts, reviewing recent activity for unfamiliar devices, and regularly checking installed browser extensions for unknown entries.

Analysts warn that the tactics demonstrated in this campaign could reappear in future attacks, prompting calls for tighter vetting of extensions and greater user awareness. As browsers continue to serve as gateways to cloud services, the line between convenience and vulnerability grows thinner, underscoring the need for ongoing vigilance from both platform providers and everyday users.

Source: GBHackers
Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related