Malicious Chrome Extension Sideload via --load-extension from User-Writable Path (via process_creation)

PremiumReviewedSigma · High · v1
Category
process_creation
Author
HuntRule
Published
2026-07-12
Updated
2026-08-28

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects a Chromium-based browser launched with the --load-extension flag pointing to a user-writable AppData or Public directory. The Ducktail campaign drops a malicious extension into the Chrome User Data folder and injects it through a LNK shortcut using --load-extension to steal session cookies and hijack business accounts, so this command line indicates unauthorized extension loading.

Related detections9 linkedT1539 — drag to rearrange
Possible Citrix Bleed Session Token Leak via OpenID Configuration Endpoint (CVE-2023-4966) (via webserver)
Suspicious Browser Extension Sideload From a User Path (via process_creation)
Uncommon Browser Launched with Remote Debugging Port for Cookie Theft (via process_creation)
Suspicious Chrome Remote Debugging Port for Browser Session Theft
Suspicious Microsoft Edge Unpacked Extension Load via UNC6692 Edgecution
Suspicious Entra Sign-In to OfficeHome with axios User Agent
Possible Citrix NetScaler CVE-2023-4966 Session Token Disclosure
Suspicious Edgecution Malicious Extension Load via Headless Edge (via process_creation)
Suspicious Access to Chrome Login Data on macOS (via process_creation)
Malicious Chrome Extension Sideload via --load-extension from User-Writable Path (via process_creation)
Pivot detection · T1539 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.