PULSE NAME
Cyberhaven Extension Compromise: TLS Certificates Reveal Hidden Infrastructure
WHITE AlienVault 2025-01-10 Modified: 2025-01-10
66
IOCs
HIGH VOLUME
A phishing attack targeting a Cyberhaven employee led to the compromise of their Google Chrome extension. The attacker published a malicious version on the Chrome Web Store, active for 24 hours, capable of exfiltrating cookies and session data. Analysis of IP addresses and domains revealed connections to a broader campaign targeting Facebook advertising accounts. A TLS certificate linked previously reported infrastructure to additional connections, suggesting a long-running operation. The infrastructure, primarily hosted on The Constant Company network, showed consistent domain patterns mimicking known organizations and extensions dating back to early 2024. While similarities exist with groups like Savvy Seahorse, further analysis is needed to establish definitive links.
Indicators of Compromise (1 / 66 total)
All FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 714936fff8b5a1fdfb793470a8b8bc0096dd1ffcf4ec2154826196b043f5ef69 2025-01-10