Threat reportMalwareTL-2026-2235

Superior Campaign: 19 Chrome and Edge Extensions Weaponized to Drain Crypto Wallets and Steal Browser/Exchange Data

highACTIVE

Superior Campaign (TL-2026-2235), also tracked as Superior, is a high-severity malware campaign, first published 2026-08-30. It has no confirmed attribution, affects Google Chrome Web Store extension platform, maps to 16 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 24 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
24Indicators of compromise

Key facts for TL-2026-2235

Threat ID
TL-2026-2235
Also known as
Superior
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
cryptocurrency, financial services, consumer individual users, web3 and defi
Target regions
Global
Detection rules
9
Indicators of compromise
24

Malware and tooling in Superior Campaign

Malware and tooling: Kraken, Superior

How Superior Campaign works

Socket's threat research team identified 19 malicious browser extensions (18 Chrome, 1 Edge) tied to a framework it tracks as 'Superior', active since approximately February 2024. The framework hijacks wallet-connect/swap buttons to drain EVM, Solana, and Tron wallets, phishes Ledger/Trezor seed phrases, steals sessions from Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask, harvests Facebook/LinkedIn credentials and browser history, and deploys ClickFix-style fake update lures, all coordinated over encrypted WebSocket C2 channels.

Socket security researcher Karlo Zanki published findings on August 27, 2026 detailing a coordinated malware framework distributed through 19 browser extensions on the Chrome Web Store and Microsoft Edge Add-ons store, tracked under the name 'Superior'. Fourteen of the extensions were built from scratch by the threat actor under innocuous branding (crypto price trackers, SEO/traffic checkers, ad-library spy tools, screenshot/OCR utilities), while five were legitimate, previously benign extensions with real install bases that the actor purchased from their original developers and later updated with malicious code — most notably 'Enable Right Click & Copy — Smart Unlock + OCR', which had accumulated roughly 70,000 Chrome installs and 10,000 Edge installs before weaponization.

Once activated, the malicious code opens a persistent WebSocket connection to actor-controlled infrastructure and pulls down JavaScript payload modules on demand, keeping the bulk of the malicious logic off the extension package itself to evade Chrome Web Store review. Deployed modules include a multi-chain wallet drainer that detects EVM-compatible, Solana, and Tron wallet activity and silently rewrites the destination of legitimate 'Connect Wallet' and 'Swap' button transactions; a hardware-wallet phishing module that renders fake Ledger and Trezor firmware-update or recovery pages to capture seed phrases; a session-theft module that harvests authentication cookies and account data from Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask; a universal form grabber; a Facebook/LinkedIn credential and session harvester; a browser-history exfiltration module; and a ClickFix-style lure that injects a fake browser-update modal instructing victims to paste and run attacker-supplied commands. Several modules strip Content-Security-Policy protections from visited pages to make the injected scripts function on sites that would otherwise block them.

At time of Socket's disclosure and BleepingComputer's follow-up coverage (August 30, 2026), Google had removed the identified extensions from the Chrome Web Store, but the Microsoft Edge Add-ons versions — including 'Allow Copy - Select & Enable Right Click' — remained live and installable. The reliance on Chrome's default silent auto-update mechanism to push the malicious versions to an already-large installed base is the campaign's core distribution technique, and the acquisition of legitimate extensions from their original developers is a supply-chain compromise pattern Socket has documented in related campaigns.

MITRE ATT&CK techniques used in TL-2026-2235

Collection

T1005 Data from Local System; T1185 Browser Session Hijacking

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

Credential Access

T1056 Input Capture; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1573 Encrypted Channel

Persistence

T1176 Software Extensions

Initial Access

T1195 Supply Chain Compromise

Discovery

T1217 Browser Information Discovery

Resource Development

T1583 Acquire Infrastructure; T1608 Stage Capabilities

Affected products and versions in Superior Campaign

  • Google — Chrome Web Store extension platform
    Vulnerable versions: 18 identified extension listings, current at time of report
    Fixed in: Extensions removed from Chrome Web Store by Google following disclosure
  • Microsoft — Edge Add-ons store extension platform
    Vulnerable versions: 1 identified extension listing ('Allow Copy - Select & Enable Right Click'), live at time of report
    Fixed in: Not yet removed as of publication

Remediation for Superior Campaign

Immediate actions

  • Remove/uninstall the 19 identified extension IDs from all managed Chrome and Edge browsers immediately, including the five acquired extensions still functioning as trojanized updates of previously legitimate tools
  • Force-revoke and rotate session cookies/API tokens for Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask accounts used on any browser that had one of the flagged extensions installed
  • Treat any Ledger or Trezor seed phrase entered through a browser-rendered 'recovery' or 'firmware update' page during the exposure window as compromised and migrate funds to a new wallet
  • Block the identified C2 and payload-hosting domains at the DNS/proxy layer

Workarounds

  • Disable non-essential browser extensions, particularly right-click/copy-enablers, screenshot/OCR tools, and crypto price-tracking extensions, until vetted

Longer-term hardening

  • Deploy enterprise extension allowlisting/blocklisting via Chrome/Edge managed policy (ExtensionInstallBlocklist / ExtensionInstallAllowlist) rather than relying on marketplace vetting alone
  • Monitor for extension ownership/publisher changes on installed extensions, since actor acquisition of dormant or actively-maintained extensions from original developers is the primary distribution vector here
  • Educate crypto-holding users that hardware wallet recovery/firmware flows should never be completed inside a browser tab prompted by a webpage or extension pop-up
  • Add browser extension WebSocket C2 behavior (persistent background-worker sockets to non-vendor domains) to EDR/network detection content

Timeline of Superior Campaign

  • Socket assesses the earliest Superior campaign extension activity to approximately February 2024 (precise day not disclosed), marking the start of the wallet-drainer framework's deployment via browser extensions.
  • Approximate start of the roughly six-month window Socket describes in which previously legitimate, high-install extensions such as 'Enable Right Click & Copy — Smart Unlock + OCR' (70,000 Chrome / 10,000 Edge installs) were purchased from their original developers and pushed malicious updates.
  • The Hacker News publishes independent coverage corroborating Socket's findings, the 'Superior' campaign name, and Karlo Zanki's attribution.
  • Socket security researcher Karlo Zanki publishes technical analysis identifying 19 malicious extensions (18 Chrome, 1 Edge) tied to the 'Superior' wallet-drainer and credential-theft framework.
  • The Microsoft Edge Add-ons version of the acquired extension ('Allow Copy - Select & Enable Right Click') remains available for download at time of publication, unlike its removed Chrome counterparts.
  • Google removes the 18 identified malicious extensions from the Chrome Web Store following disclosure.
  • BleepingComputer reports on the Socket findings, summarizing the framework's wallet-connect hijacking, seed-phrase phishing, exchange session theft, and ClickFix-style lures.

Sources cited for Superior Campaign

Detection coverage for TL-2026-2235

As of 2026-08-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2235 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
24 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats