Threat reportMalwareTL-2026-1976

Fake GoogleTranslate Chrome Extension Enables Remote Browser Control and Credential Theft via Rust Loader, AutoIt, and Stealc v2

highACTIVE

Fake GoogleTranslate Chrome Extension Enables Remote Browser (TL-2026-1976) is a high-severity malware campaign, first published 2026-08-10. It has no confirmed attribution, affects Google Google Chrome (browser extension platform), maps to 13 MITRE ATT&CK techniques (T1036, T1059.010, T1071.001), and is covered by 9 detection rules and 13 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
13MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
13Indicators of compromise

Key facts for TL-2026-1976

Threat ID
TL-2026-1976
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Detection rules
9
Indicators of compromise
13

Malware and tooling in Fake GoogleTranslate Chrome Extension Enables Remote Browser

Malware and tooling: Rakhni, Stealc, TRANSLATEXT - S1201, AutoIt, Rust

How Fake GoogleTranslate Chrome Extension Enables Remote Browser works

A malicious Chrome extension impersonating Google Translate streams victims' live browser windows to attackers, accepts remote mouse/keyboard input, injects attacker JavaScript, overlays phishing iframes while preserving the real address bar, hijacks proxy settings, and harvests browsing history, bookmarks, extension details, cookies, and credentials. VMRay documented a Rust-loader -> AutoIt -> Stealc v2 infection chain with 4 SHA-256 hashes and 2 live C2 endpoints.

VMRay researchers documented a malicious Chrome extension impersonating Google Translate that grants attackers near-total remote control of a victim's browser session while simultaneously operating as a credential- and cookie-harvesting platform. The infection chain is three-staged: a Rust-based loader (SHA-256 7ba2c663d76d2d353a02d815381f22a1b04b2032162b1559455d1f456432340a) first executes on the host and deploys an AutoIt script (SHA-256 4f82542f68d2e677fb64ba986c8d5f3a04017a1bf7a11d375e52f950e32eb262), which in turn drops the Stealc v2 information stealer (SHA-256 45c7d791fab4128fb495f359ed641e217883f132bb8f13c1e181caf5f5279a34). The fake GoogleTranslate extension package itself carries SHA-256 02e9da11f035bd4e18338ddd78e2818da49e7d1c8f614e9b329afaf581c33301. The exact distribution vector and the precise filename used for the extension in this campaign were not disclosed in VMRay's reporting and are not asserted here.

Once installed, the extension abuses over-broad Chrome extension API permissions (tab access, scripting, and web-request interception) to give the attacker a real-time view of the victim's Chrome windows plus synthetic mouse-click and keyboard-input capability, deliberately operated in unfocused/background windows so the victim does not notice cursor or window activity. The same permission set is used to inject attacker-controlled JavaScript into visited sites and to render phishing iframes on top of legitimate pages while leaving the real URL bar untouched, a classic man-in-the-browser technique that defeats casual visual inspection. A built-in proxy-hijack capability lets the attacker route the victim's browsing traffic through attacker-controlled infrastructure. In parallel, the extension/Stealc v2 payload collects browsing history, saved bookmarks, installed-extension inventories, cookies, and stored credentials, enabling session/account hijacking independent of the live-control channel. Two HTTP command-and-control endpoints were observed live at the time of the report: 87.120.104[.]147:8080 and 160.20.109[.]33:80.

VMRay's writeup notes that a prior Kimsuky-linked operation used a similarly named extension file, 'GoogleTranslate.crx' -- publicly documented in 2024 as the TRANSLATEXT campaign, which was briefly hosted on a GitHub repository and targeted South Korean academics researching North Korean affairs. That resemblance is naming/branding precedent only: the current campaign carries no confirmed actor attribution, no stated targeting scope, and no evidence tying it to Kimsuky infrastructure or tradecraft beyond the shared lure name. Stealc v2, the terminal payload, is a widely distributed commodity infostealer/loader (introduced March 2025) known industry-wide for a redesigned, RC4-encrypted, JSON-based HTTP C2 protocol, multi-monitor screenshot capture, a unified file grabber, geofenced/HWID-aware payload delivery, and MSI/PowerShell-based delivery options; a Microsoft DCU and Europol operation disrupted over 200 Stealc/Amadey C2 domains and IPs on 2026-06-24, though the family and its affiliates remain active on replacement infrastructure -- consistent with the fresh C2 endpoints seen in this campaign.

MITRE ATT&CK techniques used in TL-2026-1976

Defense Evasion

T1036 Masquerading; T1564.003 Hidden Window

Execution

T1059.010 AutoHotKey & AutoIT

Command and Control

T1071.001 Web Protocols; T1090 Proxy; T1219 Remote Access Tools; T1573.001 Symmetric Cryptography

Collection

T1113 Screen Capture; T1185 Browser Session Hijacking

Persistence

T1176 Software Extensions

Discovery

T1217 Browser Information Discovery

Credential Access

T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers

Affected products and versions in Fake GoogleTranslate Chrome Extension Enables Remote Browser

  • Google — Google Chrome (browser extension platform)
    Vulnerable versions: N/A - impersonation/social-engineering threat, not a version-specific Chrome vulnerability
    Fixed in: N/A - remove the malicious extension; no product patch applies

Remediation for Fake GoogleTranslate Chrome Extension Enables Remote Browser

Patches

  • No vendor patch applies -- this is a malicious third-party extension impersonating Google Translate, not a Chrome or Google Translate product vulnerability

Immediate actions

  • Block the two observed C2 endpoints (87.120.104.147:8080 and 160.20.109.33:80) at the network perimeter/proxy
  • Identify and remove any Chrome extension matching the documented SHA-256 hashes across managed endpoints
  • Force-revoke and rotate browser-stored credentials and session cookies on any host where the extension was installed
  • Audit installed Chrome extensions for excessive tabs/scripting/webRequest permissions and remove unrecognized or unverified extensions

Workarounds

  • Disable third-party extension installs outside the Chrome Web Store admin allowlist via managed Chrome policy
  • Restrict extension permissions requiring host access to all sites via enterprise policy where feasible

Longer-term hardening

  • Enforce Chrome ExtensionInstallBlocklist/ExtensionInstallAllowlist enterprise policy to restrict installs to a vetted list
  • Deploy EDR/browser-telemetry coverage capable of detecting hidden/unfocused Chrome windows and anomalous extension network calls
  • Monitor for Stealc v2's characteristic RC4-encrypted JSON-over-HTTP C2 pattern on port 80/8080 egress
  • User awareness training on browser-extension impersonation of common utilities (translation tools, ad blockers, PDF viewers)

Timeline of Fake GoogleTranslate Chrome Extension Enables Remote Browser

  • Kimsuky-linked actor creates the GitHub account later used to host the prior 'GoogleTranslate.crx'-named TRANSLATEXT extension, the naming precedent VMRay cites for this new campaign
  • TRANSLATEXT extension files uploaded to that GitHub repository under the filename GoogleTranslate.crx
  • TRANSLATEXT files removed from the GitHub repository within roughly 24 hours, indicating deliberately limited exposure
  • Stealc v2 introduced, adding a redesigned RC4-encrypted JSON C2 protocol, multi-monitor screenshot capture, and MSI/PowerShell delivery options
  • Microsoft Digital Crimes Unit and Europol disrupt over 200 Stealc and Amadey C2 domains/IPs, though the families remain active on other infrastructure
  • Cyber Security News publishes the technical writeup of VMRay's findings, the primary source for this record
  • VMRay researchers document the fake GoogleTranslate Chrome extension campaign, identifying the Rust loader -> AutoIt -> Stealc v2 chain and two live C2 endpoints

Sources cited for Fake GoogleTranslate Chrome Extension Enables Remote Browser

Detection coverage for TL-2026-1976

As of 2026-08-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1976 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
13 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats