Ghotala.wtf
English

Choose your language

Report a new scam

Choose your language

All languages

Malicious Browser Extension Scam

In short

A browser extension that appears useful or legitimate is malicious The objective is typically to steal data/credentials or manipulate activity for cyber/financial fraud.

What it is

The extension requests permissions that allow it to observe or manipulate browsing/account activity. The victim is then pushed to install the extension and grant its requested permissions.

How it starts

A browser extension that appears useful or legitimate is malicious.

What they tell you

The extension requests permissions that allow it to observe or manipulate browsing/account activity

What they want you to do

Install the extension and grant its requested permissions

How you lose money

steal data/credentials or manipulate activity for cyber/financial fraud

What happens next

After the first successful step, the fraudster may demand more money/information, deepen account or device access, or disappear.

Warning signs

trust | convenience | malicious extension | permission abuse | credential theft

Where this is documented

India — officially documented by an Indian authority/regulator

How to avoid it

Do not sideload unknown apps/executables/extensions or grant accessibility/screen-sharing permissions to unverified parties; update and scan the device.

If it already happened

Contact the bank/payment provider immediately if money moved; report financial cyber fraud promptly via 1930 and cybercrime.gov.in; preserve messages, transaction IDs, phone numbers and URLs. From a clean device, revoke sessions, change credentials and review account recovery/security settings.

Known variants

  • Browser Extension Credential-Theft VariantA malicious extension observes or steals sensitive browsing/account information.

Sources

Published documents this page draws on.

Already sent money or shared something?

What to do now

Malicious Browser Extension Scam — Scam types