
Rilide Malware Evolves: Chrome Extension Manifest V3 and PowerPoint Guides Target Enterprise Users
Researchers have discovered an updated version of the Rilide malware that targets Chromium-based web browsers, exhibiting a higher level of sophistication and adapting to the Chrome Extension Manifest V3. The malware is capable of stealing sensitive data and cryptocurrency, disabling other browser add-ons, harvesting browsing history and cookies, collecting login credentials, taking screenshots, and injecting malicious scripts. It is sold on dark web forums for $5,000. The updated version of Rilide overlaps with malware known as CookieGenesis and uses the controversial Chrome Extension Manifest V3. The malware impersonates legitimate apps and employs vishing tactics to deceive users into installing it. The threat actors behind Rilide also use a PowerShell loader to modify the browser's Secure Preferences file and have connections to other websites serving malware.
