New Stanley toolkit builds Chrome extensions that spoof websites
Varonis Threat Labs has uncovered a new malware-as-a-service toolkit called Stanley, marketed on Russian-language cybercrime forums for roughly 2,000 to 6,000 dollars. Stanley lets attackers build malicious browser extensions that can be published to the Chrome Web Store and then intercept and spoof legitimate websites by overlaying fake content while the real URL remains visible in the address bar. The toolkit's promised Web Store approval and turnkey management panel lower the barrier for less-skilled operators. Extensions distributed via Stanley have been seen maintaining persistent command-and-control communication and receiving dynamic phishing rule updates.
What this means for your organisation
The standard advice to check the address bar stops working here. When the overlay lives inside the browser, your bank, payroll system and cloud service all look correct right up to the moment credentials are entered. For organisations, that means browser extensions must be treated as software with access to everything employees do, not as personal tweaks each individual manages alone.
Berigo recommends
- Introduce an allowlist for browser extensions on corporate browsers and block the rest.
- Audit extensions already installed on employee machines and remove anything without a stated business need.
- Use phishing-resistant sign-in, such as passkeys or hardware keys, for your most important services.
- Update awareness training so staff know a correct URL is no longer proof that a page is genuine.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch