FORENSIA

ATT&CK · T1176

Software Extensions

Tactics: persistence

About

Adversaries may abuse software extensions to establish persistent access to victim systems. Software extensions are modular components that enhance or customize the functionality of software applications, including web browsers, Integrated Development Environments (IDEs), and other platforms. Extensions are typically installed via official marketplaces, app stores, or manually loaded by users, and they often inherit the permissions and access levels of the host application. Malicious extensions can be introduced through various methods, including social engineering, compromised marketplaces, or direct installation by users or by adversaries who have already gained access to a system. Malicious extensions can be named similarly or identically to benign extensions in marketplaces. Security mechanisms in extension marketplaces may be insufficient to detect malicious components, allowing adversaries to bypass automated scanners or exploit trust established during the installation process. Adversaries may also abuse benign extensions to achieve their objectives, such as using legitimate functionality to tunnel data or bypass security controls. The modular nature of extensions and their integration with host applications make them an attractive target for adversaries seeking to exploit trusted software ecosystems. Detection can be challenging due to the inherent trust placed in extensions during installation and their ability to blend into normal application workflows.

Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

0 known groups

No mapped actors.

Software

0 malware/tools implement this

None mapped.

Corpus indicators tagged with this technique

178 indicators in the corpus carry T1176.

IndicatorTypeFamilySevSrc
a247a63644c3475f436d076f55523ea39afd8c41hash801
65a052908f79efc7878d6799fd3b7be1e30eba49fa05156d7e5239b2b9ddaf71sha2568060
52886aab179f26421678ff23af1b0fabf0a17ffbb534369cdbbac8008cbed8e7hashphishing802
91b9381d19b2e6a2db5cc0307167979b502731cb3fb50da684479e9ed35261aahashphishing802
c984787ccd787629542da68302ed4ceb48fc7e458eab1c15bf45c3070883d26ahash802
ffd773f157df70291f0910a45a1d8d9ahash801
2c5bc9e95e1e9b73e3ba8870a008802899866a2c0e2e10112aefddf7a96af04ehash801
524c953e23ff8b768206cf33a529c11ac5510e47cbf6246db79ee671d1231716hash802
62761f38ed194c59abe15c49f09f0ebc431ac852c965180c9327ed84d3a454fbhashphishing802
6c3f61d46d4de26b9cb16808bf17c33ae69f651a4b879e7b5612ff7f548e2a82hash801
bb1e6e2650d3d77d732c5eb5176011f914dd87dfhash801
c40126fea6ed24652a3e4e19205075cb02cca3e2hash801
f544bfab72d380cc20692d8ec9d31ea666785fe225dccd55beab29a3c0fdfad2hash801
fc091ddb4d845280aeb7745cfdb6b7cb0013abc35db9e634f055b8e8fb0b5b1ehash801
d5e9288693aa745dc89368deac677e7ea1ec81e663283af30838cdae189b7a7ehashphishing802
134517796178a150a1585672be134169d6877082b598d840baa3f37b0222be26hash801
3d1158884fb339b3328bd330fcc27598e1f1c94bcac39e75d1a272afa4deee1asha256ransomware801
32da1437a2734224406c7e5e8d756f0c0cd58c0c959478571cbfc0cd564d018ahash801
a08d8e63b0cd3638fb40b8e6da546e26da69439597565827f9cec87915f78568sha256ransomware801
605169623267c4eb73693b22b811dc7ahash801
f8cbe44fde6914bc8d06426c03c92ed536c891470292e567a586b54af29c2442hash802
638b0a77a6d686849a78b500adf5e565hash801
4c0d9b802c075be79e9edb52d88f8dd72e6904f5c58267213745818470945c78hashphishing802
b4aa7255af4b016586090a5b451300fahash801
808e7154b7af2bc7a4b28d577297c55f77221c355191cbe00f9f1810b6d4a619hashphishing802
bf90fb31e6024d7e6616f5acd0e8aa28738a9095a508c1a986e1e974cb9e79a0hash801
bb10adac5b0124efedfe71102c1d5638135ec9e1cde8c8cb3353c5ed91bb9f81hashphishing802
cc4f048e66c5ab3c0f1d767bb8fc464d082641f4888ea3cd14ea3775077c4bf2hash801
d3ebce2f05fe91a8260e87fd11a6ea17c156703d081b3f91d9bbe5fd6aeedc10hashphishing802
2812e0847d472cb8870c94f463331dbe53b84135132b9bf5f6d84c2382be628fhashphishing802

Showing the top 30 by severity of 178.