Threat reportMalwareTL-2026-1976
Fake GoogleTranslate Chrome Extension Enables Remote Browser Control and Credential Theft via Rust Loader, AutoIt, and Stealc v2
Fake GoogleTranslate Chrome Extension Enables Remote Browser (TL-2026-1976) is a high-severity malware campaign, first published 2026-08-10. It has no confirmed attribution, affects Google Google Chrome (browser extension platform), maps to 13 MITRE ATT&CK techniques (T1036, T1059.010, T1071.001), and is covered by 9 detection rules and 13 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 13MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 13Indicators of compromise
Key facts for TL-2026-1976
- Threat ID
- TL-2026-1976
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Detection rules
- 9
- Indicators of compromise
- 13
Malware and tooling in Fake GoogleTranslate Chrome Extension Enables Remote Browser
Malware and tooling: Rakhni, Stealc, TRANSLATEXT - S1201, AutoIt, Rust
How Fake GoogleTranslate Chrome Extension Enables Remote Browser works
A malicious Chrome extension impersonating Google Translate streams victims' live browser windows to attackers, accepts remote mouse/keyboard input, injects attacker JavaScript, overlays phishing iframes while preserving the real address bar, hijacks proxy settings, and harvests browsing history, bookmarks, extension details, cookies, and credentials. VMRay documented a Rust-loader -> AutoIt -> Stealc v2 infection chain with 4 SHA-256 hashes and 2 live C2 endpoints.
VMRay researchers documented a malicious Chrome extension impersonating Google Translate that grants attackers near-total remote control of a victim's browser session while simultaneously operating as a credential- and cookie-harvesting platform. The infection chain is three-staged: a Rust-based loader (SHA-256 7ba2c663d76d2d353a02d815381f22a1b04b2032162b1559455d1f456432340a) first executes on the host and deploys an AutoIt script (SHA-256 4f82542f68d2e677fb64ba986c8d5f3a04017a1bf7a11d375e52f950e32eb262), which in turn drops the Stealc v2 information stealer (SHA-256 45c7d791fab4128fb495f359ed641e217883f132bb8f13c1e181caf5f5279a34). The fake GoogleTranslate extension package itself carries SHA-256 02e9da11f035bd4e18338ddd78e2818da49e7d1c8f614e9b329afaf581c33301. The exact distribution vector and the precise filename used for the extension in this campaign were not disclosed in VMRay's reporting and are not asserted here.
Once installed, the extension abuses over-broad Chrome extension API permissions (tab access, scripting, and web-request interception) to give the attacker a real-time view of the victim's Chrome windows plus synthetic mouse-click and keyboard-input capability, deliberately operated in unfocused/background windows so the victim does not notice cursor or window activity. The same permission set is used to inject attacker-controlled JavaScript into visited sites and to render phishing iframes on top of legitimate pages while leaving the real URL bar untouched, a classic man-in-the-browser technique that defeats casual visual inspection. A built-in proxy-hijack capability lets the attacker route the victim's browsing traffic through attacker-controlled infrastructure. In parallel, the extension/Stealc v2 payload collects browsing history, saved bookmarks, installed-extension inventories, cookies, and stored credentials, enabling session/account hijacking independent of the live-control channel. Two HTTP command-and-control endpoints were observed live at the time of the report: 87.120.104[.]147:8080 and 160.20.109[.]33:80.
VMRay's writeup notes that a prior Kimsuky-linked operation used a similarly named extension file, 'GoogleTranslate.crx' -- publicly documented in 2024 as the TRANSLATEXT campaign, which was briefly hosted on a GitHub repository and targeted South Korean academics researching North Korean affairs. That resemblance is naming/branding precedent only: the current campaign carries no confirmed actor attribution, no stated targeting scope, and no evidence tying it to Kimsuky infrastructure or tradecraft beyond the shared lure name. Stealc v2, the terminal payload, is a widely distributed commodity infostealer/loader (introduced March 2025) known industry-wide for a redesigned, RC4-encrypted, JSON-based HTTP C2 protocol, multi-monitor screenshot capture, a unified file grabber, geofenced/HWID-aware payload delivery, and MSI/PowerShell-based delivery options; a Microsoft DCU and Europol operation disrupted over 200 Stealc/Amadey C2 domains and IPs on 2026-06-24, though the family and its affiliates remain active on replacement infrastructure -- consistent with the fresh C2 endpoints seen in this campaign.
MITRE ATT&CK techniques used in TL-2026-1976
Defense Evasion
T1036 Masquerading; T1564.003 Hidden Window
Execution
Command and Control
T1071.001 Web Protocols; T1090 Proxy; T1219 Remote Access Tools; T1573.001 Symmetric Cryptography
Collection
T1113 Screen Capture; T1185 Browser Session Hijacking
Persistence
Discovery
T1217 Browser Information Discovery
Credential Access
T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers
Affected products and versions in Fake GoogleTranslate Chrome Extension Enables Remote Browser
- Google — Google Chrome (browser extension platform)
Vulnerable versions: N/A - impersonation/social-engineering threat, not a version-specific Chrome vulnerability
Fixed in: N/A - remove the malicious extension; no product patch applies
Remediation for Fake GoogleTranslate Chrome Extension Enables Remote Browser
Patches
- No vendor patch applies -- this is a malicious third-party extension impersonating Google Translate, not a Chrome or Google Translate product vulnerability
Immediate actions
- Block the two observed C2 endpoints (87.120.104.147:8080 and 160.20.109.33:80) at the network perimeter/proxy
- Identify and remove any Chrome extension matching the documented SHA-256 hashes across managed endpoints
- Force-revoke and rotate browser-stored credentials and session cookies on any host where the extension was installed
- Audit installed Chrome extensions for excessive tabs/scripting/webRequest permissions and remove unrecognized or unverified extensions
Workarounds
- Disable third-party extension installs outside the Chrome Web Store admin allowlist via managed Chrome policy
- Restrict extension permissions requiring host access to all sites via enterprise policy where feasible
Longer-term hardening
- Enforce Chrome ExtensionInstallBlocklist/ExtensionInstallAllowlist enterprise policy to restrict installs to a vetted list
- Deploy EDR/browser-telemetry coverage capable of detecting hidden/unfocused Chrome windows and anomalous extension network calls
- Monitor for Stealc v2's characteristic RC4-encrypted JSON-over-HTTP C2 pattern on port 80/8080 egress
- User awareness training on browser-extension impersonation of common utilities (translation tools, ad blockers, PDF viewers)
Timeline of Fake GoogleTranslate Chrome Extension Enables Remote Browser
- Kimsuky-linked actor creates the GitHub account later used to host the prior 'GoogleTranslate.crx'-named TRANSLATEXT extension, the naming precedent VMRay cites for this new campaign
- TRANSLATEXT extension files uploaded to that GitHub repository under the filename GoogleTranslate.crx
- TRANSLATEXT files removed from the GitHub repository within roughly 24 hours, indicating deliberately limited exposure
- Stealc v2 introduced, adding a redesigned RC4-encrypted JSON C2 protocol, multi-monitor screenshot capture, and MSI/PowerShell delivery options
- Microsoft Digital Crimes Unit and Europol disrupt over 200 Stealc and Amadey C2 domains/IPs, though the families remain active on other infrastructure
- Cyber Security News publishes the technical writeup of VMRay's findings, the primary source for this record
- VMRay researchers document the fake GoogleTranslate Chrome extension campaign, identifying the Rust loader -> AutoIt -> Stealc v2 chain and two live C2 endpoints
Sources cited for Fake GoogleTranslate Chrome Extension Enables Remote Browser
- Fake GoogleTranslate Chrome Extension Lets Attackers Remotely Control Your Browsers
- Kimsuky Using TRANSLATEXT Chrome Extension to Steal Sensitive Data
- Kimsuky Deploys TRANSLATEXT Chrome Extension Targeting South Korean Academia
- Kimsuky APT Attack Detection: North Korean Hackers Abuse the TRANSLATEXT Chrome Extension to Steal Sensitive Data
- StealC V2: A Sharper, Stealthier Infostealer Emerges
- StealC V2 Malware Enhances Stealth and Expands Data Theft Features
- I StealC You: Tracking the Rapid Changes To StealC
- StealC infrastructure takedown assisted by AI analysis, C2 infiltration
- StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them
Detection coverage for TL-2026-1976
As of 2026-08-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1976 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.