Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Aug 30, 2026
- Feed role
- C2 / Distribution
- Host form
- 2 IP / 8 hostnames
C2 tracking
Derp observations, rolling seven-day window
Samples
5d77cc84dcea957da429322bb39b9d0badcaec53604f240d88690c7ea2a40866 a0ea0cdeb94e481388df2324150f6dda983de4eb3819a0f6bc8a087de9aadf8f bb8a2d4cd68122519525cb162652bfa862e7bf159600ca7dc58926cb31dbdde5 292972d7871a446134f522c3961e67da00405be57c34da5208c5246e44bf459f Reporting
Malicious and unwanted browser extensions continued to pose a significant threat to users, including through official browser stores and add-ons disguised as legitimate tools. Kaspersky reported that from January 2020 through June 2022, more than 6 million users were blocked from downloading malware, adware, or riskware presented as browser extensions, with adware making up most detections. The report identified several prominent families, including WebSearch, DealPly-related extensions, AddScript, and FB Stealer, each using different delivery and monetization methods. The extensions were distributed through third-party software bundles, malicious updates, and cases where an extension changed hands or a developer account was hijacked after publication. Their activity ranged from affiliate abuse and cookie stuffing to covert script execution and credential theft, with FB Stealer highlighted as particularly dangerous because it steals Facebook session cookies and enables account hijacking. The findings underscored that browser extensions can become a persistent attack surface even when they appear benign, especially when users grant broad permissions or install unnecessary add-ons.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.