Massive spying on users of Google's Chrome shows new security weakness | The Business Standard
Skip to main content
  • Latest
  • Economy
    • Banking
    • Stocks
    • Industry
    • Analysis
    • Bazaar
    • RMG
    • Corporates
    • Aviation
  • Videos
    • TBS Today
    • TBS Stories
    • TBS World
    • News of the day
    • TBS Programs
    • Podcast
    • Editor's Pick
  • World+Biz
  • Features
    • Panorama
    • The Big Picture
    • Pursuit
    • Habitat
    • Thoughts
    • Splash
    • Mode
    • Tech
    • Explorer
    • Brands
    • In Focus
    • Book Review
    • Earth
    • Food
    • Luxury
    • Wheels
  • Subscribe
    • Get the Paper
    • Epaper
    • GOVT. Ad
  • More
    • Sports
    • TBS Graduates
    • Bangladesh
    • Supplement
    • Infograph
    • Archive
    • Gallery
    • Long Read
    • Interviews
    • Offbeat
    • Magazine
    • Climate Change
    • Health
    • Cartoons
  • বাংলা
The Business Standard

Friday
July 18, 2025

Sign In
Subscribe
  • Latest
  • Economy
    • Banking
    • Stocks
    • Industry
    • Analysis
    • Bazaar
    • RMG
    • Corporates
    • Aviation
  • Videos
    • TBS Today
    • TBS Stories
    • TBS World
    • News of the day
    • TBS Programs
    • Podcast
    • Editor's Pick
  • World+Biz
  • Features
    • Panorama
    • The Big Picture
    • Pursuit
    • Habitat
    • Thoughts
    • Splash
    • Mode
    • Tech
    • Explorer
    • Brands
    • In Focus
    • Book Review
    • Earth
    • Food
    • Luxury
    • Wheels
  • Subscribe
    • Get the Paper
    • Epaper
    • GOVT. Ad
  • More
    • Sports
    • TBS Graduates
    • Bangladesh
    • Supplement
    • Infograph
    • Archive
    • Gallery
    • Long Read
    • Interviews
    • Offbeat
    • Magazine
    • Climate Change
    • Health
    • Cartoons
  • বাংলা
FRIDAY, JULY 18, 2025
Massive spying on users of Google's Chrome shows new security weakness

Tech

Reuters
18 June, 2020, 11:25 am
Last modified: 18 June, 2020, 11:33 am

Related News

  • Trump backs national security adviser after Yemen war security breach
  • China court jails journalist for seven years on spy charges, family says
  • China warns students 'beautiful women, handsome guys' could lure them into spying
  • Eight EU countries call for restricting Russian diplomats' movement
  • Britain summons Chinese ambassador over Hong Kong spying charges

Massive spying on users of Google's Chrome shows new security weakness

Google declined to discuss how the latest spyware compared with prior campaigns, the breadth of the damage, or why it did not detect and remove the bad extensions on its own despite past promises to supervise offerings more closely

Reuters
18 June, 2020, 11:25 am
Last modified: 18 June, 2020, 11:33 am
Photo: Reuters
Photo: Reuters

A newly discovered spyware effort attacked users through 32 million downloads of extensions to Google's market-leading Chrome web browser, researchers at Awake Security told Reuters, highlighting the tech industry's failure to protect browsers as they are used more for email, payroll and other sensitive functions.

Alphabet Inc's Google said it removed more than 70 of the malicious add-ons from its official Chrome Web Store after being alerted by the researchers last month.

"When we are alerted of extensions in the Web Store that violate our policies, we take action and use those incidents as training material to improve our automated and manual analyses," Google spokesman Scott Westover told Reuters.

The Business Standard Google News Keep updated, follow The Business Standard's Google news channel

Most of the free extensions purported to warn users about questionable websites or convert files from one format to another. Instead, they siphoned off browsing history and data that provided credentials for access to internal business tools.

Based on the number of downloads, it was the most far-reaching malicious Chrome store campaign to date, according to Awake co-founder and chief scientist Gary Golomb.

Google declined to discuss how the latest spyware compared with prior campaigns, the breadth of the damage, or why it did not detect and remove the bad extensions on its own despite past promises to supervise offerings more closely.

It is unclear who was behind the effort to distribute the malware. Awake said the developers supplied fake contact information when they submitted the extensions to Google.

"Anything that gets you into somebody's browser or email or other sensitive areas would be a target for national espionage as well as organized crime," said former National Security Agency engineer Ben Johnson, who founded security companies Carbon Black and Obsidian Security.

The extensions were designed to avoid detection by antivirus companies or security software that evaluates the reputations of web domains, Golomb said.

If someone used the browser to surf the web on a home computer, it would connect to a series of websites and transmit information, the researchers found. Anyone using a corporate network, which would include security services, would not transmit the sensitive information or even reach the malicious versions of the websites.

"This shows how attackers can use extremely simple methods to hide, in this case, thousands of malicious domains," Golomb said.

All of the domains in question, more than 15,000 linked to each other in total, were purchased from a small registrar in Israel, Galcomm, known formally as CommuniGal Communication Ltd.

Awake said Galcomm should have known what was happening.

In an email exchange, Galcomm owner Moshe Fogel told Reuters that his company had done nothing wrong.

"Galcomm is not involved, and not in complicity with any malicious activity whatsoever," Fogel wrote. "You can say exactly the opposite, we cooperate with law enforcement and security bodies to prevent as much as we can."

Fogel said there was no record of the inquiries Golomb said he made in April and again in May to the company's email address for reporting abusive behavior, and he asked for a list of suspect domains. Reuters sent him that list three times without getting a substantive response.

The Internet Corp for Assigned Names and Numbers, which oversees registrars, said it had received few complaints about Galcomm over the years, and none about malware.

While deceptive extensions have been a problem for years, they are getting worse. They initially spewed unwanted advertisements, and now are more likely to install additional malicious programs or track where users are and what they are doing for government or commercial spies.

Malicious developers have been using Google's Chrome Store as a conduit for a long time. After one in 10 submissions was deemed malicious, Google said in 2018 here it would improve security, in part by increasing human review.
But in February, independent researcher Jamila Kaya and Cisco Systems' Duo Security uncovered here a similar Chrome campaign that stole data from about 1.7 million users. Google joined the investigation and found 500 fraudulent extensions.

"We do regular sweeps to find extensions using similar techniques, code and behaviors," Google's Westover said, in identical language to what Google gave out after Duo's report.

Top News

Google Chrome / security breach / Spying

Comments

While most comments will be posted if they are on-topic and not abusive, moderation decisions are subjective. Published comments are readers’ own views and The Business Standard does not endorse any of the readers’ comments.

Top Stories

  • Around 99% of the cotton used in Bangladesh’s export and domestic garment production is imported. Photo: Collected
    NBR withdraws advance tax on imports of cotton, man-made fibres
  • The fire originated at 10:40pm on the 21th floor of the building. Photo: Collected
    Fire at Sena Kalyan Bhaban in Motijheel under control
  • Chief Adviser Professor Muhammad Yunus presided over a meeting of the National Consensus Commission at the State Guest House Jamuna yesterday (17 July). Photo: UNB
    CA Yunus stresses transparency in finalising July Charter

MOST VIEWED

  • Bangladesh Bank buys $313m more in second dollar auction in three days
    Bangladesh Bank buys $313m more in second dollar auction in three days
  • Representational image. File Photo: Syed Zakir Hossain/TBS
    Malaysia grants Bangladeshi workers multiple-entry visas
  • The Chattogram Custom House building in Chattogram. File Photo: Collected
    Software slowdown disrupts customs operations nationwide
  • NCP leaders are seen getting on an armoured personnel carrier (APC) of the army to leave Gopalganj following attacks on their convoy after the party's rally in the district today (16 july). Photo: Focus Bangla
    NCP leaders leave Gopalganj in army's APC following attack on convoy, clashes between AL, police
  • Renata’s manufacturing standards win european recognition
    Renata’s manufacturing standards win european recognition
  • The supporters of local Awami League and Chhatra League locked in a clash with police following attacks on NCP convoy this afternoon (16 July). Photo: Collected
    Gopalganj under curfew; 4 killed as banned AL, police clash after attack on NCP leaders

Related News

  • Trump backs national security adviser after Yemen war security breach
  • China court jails journalist for seven years on spy charges, family says
  • China warns students 'beautiful women, handsome guys' could lure them into spying
  • Eight EU countries call for restricting Russian diplomats' movement
  • Britain summons Chinese ambassador over Hong Kong spying charges

Features

Illustration: TBS

20 years of war, 7.5m tonnes of bombs, 1.3m dead: How the US razed Vietnam to the ground

1h | The Big Picture
On 17 July 2024, Dhaka University campus became a warzone with police firing tear shells and rubber bullets to control the student movement. File Photo: Rajib Dhar/TBS

17 July 2024: Students oust Chhatra League from campuses, Hasina promises 'justice' after deadly crackdown

9h | Panorama
Abu Sayeed spread his hands as police fired rubber bullets, leading to his tragic death. Photos: Collected

How Abu Sayed’s wings of freedom ignited the fire of July uprising

2d | Panorama
Illustration: TBS

Open source legal advice: How Facebook groups are empowering victims of land disputes

3d | Panorama

More Videos from TBS

Why the conflicting claims over Gopalganj autopsies?

Why the conflicting claims over Gopalganj autopsies?

2h | TBS Stories
Gopalganj violence in international media

Gopalganj violence in international media

3h | TBS World
The Philippines has become a laboratory for China's disinformation propaganda

The Philippines has become a laboratory for China's disinformation propaganda

3h | TBS World
Gopalganj clash: Army urges not to be misled by rumors

Gopalganj clash: Army urges not to be misled by rumors

5h | TBS Today
EMAIL US
contact@tbsnews.net
FOLLOW US
WHATSAPP
+880 1847416158
The Business Standard
  • About Us
  • Contact us
  • Sitemap
  • Advertisement
  • Privacy Policy
  • Comment Policy
Copyright © 2025
The Business Standard All rights reserved
Technical Partner: RSI Lab

Contact Us

The Business Standard

Main Office -4/A, Eskaton Garden, Dhaka- 1000

Phone: +8801847 416158 - 59

Send Opinion articles to - oped.tbs@gmail.com

For advertisement- sales@tbsnews.net