Skip to main content
  1. Home
  2. Computing
  3. News

This Chrome extension lets hackers remotely seize your PC

Add as a preferred source on Google

Malicious extensions on Google Chrome are being used by hackers remotely in an effort to steal sensitive information.

As reported by Bleeping Computer, a new Chrome browser botnet titled ‘Cloud9’ is also capable of logging keystrokes, as well as distributing ads and malicious code.

A depiction of a hacker breaking into a system via the use of code.
Getty Images

The browser botnet operates as a remote access trojan (RAT) for the Chromium web browser, which includes both Chrome and Microsoft Edge. As such, it’s not just login credentials that can be accessed; hackers can also launch distributed denial of service (DDoS) attacks.

Recommended Videos

The Chrome extension in question is naturally not accessible via Google’s official Chrome web store, so you may be wondering how victims are being targeted. Websites that exist to spread infections via bogus Adobe Flash Player update notifications are being used instead.

Security researchers at Zimperium have confirmed that Cloud9 infection rates have been detected in multiple regions around the world.

The foundation of Cloud9 is three central JavaScript files that can obtain information of the target system, and mine cryptocurrency on that same PC in addition to injecting scripts in order to launch browser exploits.

Multiple vulnerabilities are being exploited, Zimperium notes, including CVE-2019-11708 and CVE-2019-9810 in Firefox, CVE-2014-6332 and CVE-2016-0189 for Internet Explorer, and CVE-2016-7200 for Microsoft Edge.

Although the vulnerabilities are commonly used to install Windows malware, the Cloud9 extension can steal cookies from a browser, allowing hackers to take over valid user sessions.

Furthermore, the malware comes with a keylogger — software that can essentially send all your key presses to the attackers. A “clipper” module was also discovered in the extension, which allows the PC to access copied passwords or credit cards.

“Layer 7 attacks are usually very hard to detect because the TCP connection looks very similar to legitimate requests,” Zimperium stated. “The developer is likely using this botnet to provide a service to perform DDOS.”

Another way the threat actors behind Cloud9 generate even more illicit income is by injecting advertisements and then loading these webpages in the background to accrue ad impressions.

With Cloud9 being spotted on cybercrime forums, the operators could be selling its malicious extension to interested parties. With this in mind, always double-check if you’re installing anything on your browser from an unofficial source and enable two-factor authentication where possible.

Zak Islam
Former Contributor
Zak covers the latest news in the technology world, particularly the computing field. A fan of anything pertaining to tech…
What’s the Right Laptop for a Student on a $1,000 Budget?
The best college laptop isn't the one with the longest spec sheet. It's the one that fits your budget and the way you'll actually use it.
Dell XPS 14 Review: Sticker

This post is brought to you in paid partnership with Dell

Buying a laptop for college isn't a decision made in isolation. Tuition, textbooks, housing, meal plans, transportation, and course materials all compete for the same budget, leaving most families with one question before the semester begins: how much is enough to spend on a laptop without paying for features that may never get used?

Read more
Siri is about to hear everything you say, but Apple’s privacy approach has me cautiously on board
Apple's new Audio Intelligence features want to hear almost everything you say. A privacy document released alongside them explains why I am mostly okay with that.
Apple Watch Audio Intelligence features

Apple used its September 2026 launch event to enter a feature category it has mostly avoided until now: ambient listening. Siri Recap, Live Rewind, Music Recognition with Shazam, and Sound Recognition all landed on the Apple Watch Series 12 and Apple Watch Ultra 4. All four depend on the watch microphone picking up sound around you far more often than any previous Apple product has.

Siri Recap listens for conversations throughout your day and turns them into short AI summaries you can check later. Live Rewind is smaller in scope but arguably more useful day-to-day. It transcribes the last 15 seconds of whatever was just said with a double-press of the crown. This is perfect for catching a name, a book title, or directions you missed the first time. Music Recognition uses Shazam to identify songs playing nearby without you lifting a finger, much like Now Playing on Google's Pixel devices. Sound Recognition is a useful accessibility feature that listens for sirens, doorbells, and alarms to alert users who have a hearing impairment.

Read more
Can You Turn a Mini PC Into a Local AI Agent?
Furniture, Table, Computer

This post is brought to you in paid partnership with MSI

Not every AI task needs the scale of the cloud. An employee searching company documents, a retail kiosk answering product questions, or a digital sign reacting to customer behavior all need fast responses, but they don't necessarily need to send every prompt to a remote data center. Running those workloads locally reduces latency, keeps sensitive information closer to where it's generated, and can lower the ongoing cost of AI deployments. As a result, many organizations are moving toward hybrid AI architectures that handle routine requests on-device while reserving cloud models for tasks that genuinely need more processing power.

Read more