Keypoints
- The campaign used 16 malicious modules with distinct functions.
- Some extensions were initially legitimate before malware was added through updates.
- The malware opened an encrypted WebSocket connection to C2 servers and injected scripts into websites.
- It targeted crypto wallets, account credentials, browser history, and Facebook and LinkedIn data.
- Victims are advised to change passwords and move crypto assets to new wallets.