ISC StormCast for Friday, February 5th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 5 February 2021
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, February 5th, 2021 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich. And today I'm recording from Jacksonville, Florida. |
| 0:14.1 | Today we got an interesting diary by Boyan. Boyan recently investigated a compromise that was performed by a somewhat more advanced adversary |
| 0:26.9 | and targeted against a particular company. |
| 0:30.9 | After this attacker was able to compromise a desktop, |
| 0:35.8 | they used a Google Chrome extension in order to achieve persistence |
| 0:40.6 | on that desktop. |
| 0:43.2 | Google Chrome extensions, of course, are interesting because first of all, they have full |
| 0:47.1 | control over whatever you're doing in Google, and then they're a little bit more stealthy. |
| 0:53.8 | In this particular case, they actually named the Google extension. in Google and then they're a little bit more stealthy. |
| 1:01.6 | In this particular case, they actually named the Google extension ForcePoint endpoint for Windows. |
| 1:10.0 | So this looks like some legitimate software that you may get as part of the Force Point Security Suite. And then, of course, they were able to observe the user browsing |
| 1:15.0 | and they were able to exfiltrate or extract |
| 1:19.6 | any authentication tokens from sessions |
| 1:23.1 | that the user opened within that browser. |
| 1:27.2 | With these Google Chrome extensions, you essentially can write JavaScript code that's then being loaded in the browser, |
| 1:35.3 | and that has the ability to modify any page that the user visits, and that's in part the point of many Google Chrome extensions. |
| 1:45.0 | But it gets really sort of interesting is how they exfiltrated the data. |
| 1:50.0 | With Google Chrome extensions, you have some storage available on the system. |
| 1:55.0 | Now, it's not a lot of storage, I believe a total of about 100 kilobytes or so. |
| 2:00.0 | It's a simple sort of key value storage and it feels a |
| 2:03.7 | little bit like cookies. Each value, I believe, is about 8 kilobytes in size max. But in addition to |
| 2:11.7 | being able to just store the data, Google Chrome extensions also have a feature that allows |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

