New Rilide Stealer Version Targets Banking Data and Works Around Google Chrome Manifest V3

Trustwave SpiderLabs details a new version of the Rilide Stealer for Chromium-based browsers that adapts to Chrome Manifest V3, featuring modular code and data exfiltration to Telegram as well as interval-based screenshots. The report covers multiple campaigns (phishing lures, fake P2E games, and banking-targeted activity), widespread phishing sites, and a broader ecosystem including CursedChrome proxies and underground market activity around Rilide.

Keypoints

  • New Rilide Stealer version targets Chromium-based browsers and adapts to Chrome’s Manifest V3.
  • Modular architecture, code obfuscation, and capability to exfiltrate data to Telegram and perform scheduled screenshots.
  • Three in-the-wild campaigns observed: PowerPoint phishing with GlobalProtect lure; fake P2E games advertised on Twitter; and banking-data targeting in AU/UK with unique extension-loading methods.
  • Over 1,300 phishing sites impersonating banks, government services, software firms, and crypto sites, some delivering other malware like BumbleBee, IceID, or Phorpiex.
  • Rilide’s command set includes extension management, cookies/history capture, on-demand screenshots, URL/tab control, and proxy capabilities via a C2 channel.
  • Attackers use CSP workarounds, inline JavaScript execution, and a PowerShell loader to install a persistent, unsigned extension.
  • Underground activity includes Rilide being sold on forums, Git/remote loader usage, and Permhash-based clustering to track variants.

MITRE Techniques

  • [T1566.001] Phishing – Corporate phishing via PowerPoint lure and a fake Palo Alto GlobalProtect plugin. ‘The first Rilide campaign seems to target corporate users through the use of a PowerPoint phishing lure and a fake Palo Alto GlobalProtect plugin.’
  • [T1105] Ingress Tool Transfer – Downloading the malicious Rilide extension from a Bitbucket repository. ‘The loader described in the previous section was downloading a malicious Rilide extension from a Bitbucket repository.’
  • [T1059.001] PowerShell – PowerShell loader used to install extensions with a new approach that makes them permanent. ‘A PowerShell loader installing extensions from this campaign…’
  • [T1059.007] JavaScript – Inline events to execute malicious JavaScript code and remote script injection in the extension. ‘The core of the functionality relies on use of inline events to execute malicious JavaScript code.’
  • [T1113] Screen Capture – Interval-based screenshots via screenshot_rules to capture data. ‘screenshot_rules … capture active tab screenshots for every time interval.’
  • [T1041] Exfiltration Over C2 Channel – Exfiltrating stolen data to a Telegram channel. ‘exfiltrate stolen data to a Telegram channel.’
  • [T1555.003] Credentials from Web Browsers – Stealing login credentials and cookies. ‘…ability to retrieve and exfiltrate cookies and login credentials…’
  • [T1090] Proxy – Using CursedChrome to act as a browser proxy, enabling attacker to browse as the victim. ‘CursedChrome Admin Panel was observed on the server.’
  • [T1112] Modify Registry – Modifying HKCU registry keys to persist extension settings via Secure Preferences. ‘the attackers must add the registry subkey…HKCU:SOFTWAREGoogleChromePreferenceMACsextensions.settings’
  • [T1027] Obfuscated/Compressed Files and Information – Code obfuscation and evolving string encoding to hinder analysis. ‘Code obfuscation … RC4 encrypted’

Indicators of Compromise

  • [Domain] – edd2ed2.online – C2 domain used by Rilide campaigns (GlobalProtect imitation campaign).
  • [Domain] – extensionsupdate.com – C2 domain configured to load extensions in AU/UK campaigns.
  • [Domain] – frz-panel.su – Rilide C2 domain found in the infrastructure pivot.
  • [File Name] – crypto-extension.zip – Rilide Stealer extension package (hashes listed below).
  • [Hash] – 66e05bc7b8e8ccd31415e22272f03bd4 – MD5 for crypto-extension.zip.
  • [Hash] – abae2f164e073e7aab2822b507de10e731cc1b396809728452e98be6618c149f – SHA256 for crypto-extension.zip.
  • [URL] – https://download[.]hdoki[.]org/yzxdhdxsqkmvcayrtevs/Riot Revelry 1.0.2.exe – ITW loader URL used in Rilide ITW deployment.
  • [URL] – https://download[.]hdoki[.]org/yzxdhdxsqkmvcayrtevs/Night Predators 1.0.2.exe – ITW loader URL for bundled payloads.
  • [File Name] – dropper.exe – one of the loadable components used for initial access.
  • [Hash] – bc9472ab59a9625003190b2dfcd1c502 – MD5 for dropper.exe.

Read more: https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/new-rilide-stealer-version-targets-banking-data-and-works-around-google-chrome-manifest-v3/