← Threat Library
high malicious update chromeedge

RedDirection

Legitimate, long-clean Chrome and Edge extensions turned malicious via routine auto-updates. Koi found 18 (~2.3M users); Spin.AI expanded the same campaign to 36 extensions and ~16.5M users.

Disclosed July 8, 2025
Blast radius ~16.5M users
Status delisted

Overview

RedDirection weaponized previously-clean browser extensions by pushing malware in routine version updates. The extension code was clean for years before the malicious update landed on the existing install base.

Payload

Captured the URL of every page visited and exfiltrated it with a unique tracking ID to a C2 server, enabling browser hijacking, redirection to attacker-controlled sites, and credential theft via fake banking pages.

IOC note

No file hashes were published for this campaign — only extension IDs and install counts. The exact malicious version per extension was not disclosed (malware was injected across updates), so versions are left open.

Affected extensions (36)

NameStoreIDMalicious versionArchived
2048 Gamechromeiabflonngmpkalkpbjonemaamlgdgheano
Adblock Unlimited - Adblockerchromejiaopkfkampgnnkckajcbdgannoipcneno
Image Downloader - Save pictureschromedaeljdgmllhgmbdkpgnaojldjkdgkbjgyes
Web Music Downloaderchromedmbjkidogjmmlejdmnecpmfapdmidfjgno
Super Mario Bros Gamechromepegfdldddiilihjahcpdehhhfcbibipgno
Video downloader - download any videochromekfpgookelklhphhnihipmknjdgbeecgjno
Screen Capturechromepmnphobdokkajkpbkajlaiooipfcpgiono
Dictionary all over with Synonymschromeahjhlnckcgnoikkfkfnkbfengklhglpgno
Multi Chat - Messenger for WhatsAppchromedllplfhjknghhdneiblmkolbjappecbeyes
Video Downloader Onlinechromejglemppahimembneahjbkhjknnefeeiono
PiP (Picture in picture)chromenalkmonnmldhpfcpdlbdpljlaajlaphhyes
Mute Tab - Silent in a clickchromeinhefjomnpfkkegfklclbjhkifmpkkmnno
Dark Mode for Chromechromejhhjdfldilccfllhlbjdlhknlfbhpgegno
Good Video Downloaderchromemhpcabliilgadobjpkameggapnpeppdgno
Flash Player Enablerchromeeplfglplnlljjpeiccbgnijecmkeimedno
Auto HD & Additions for Youtubechromelagdcjmbchphhndlbpfajelapcodekllno
What Font - find fontchromeacpcapnaopbhbelhmbbmppghilclpkepno
Floating Video with Playback Controlschromepnanegnllonoiklmmlegcaajoicfifcmyes
Emoji keyboard onlinechromekgmeffmlnkfnjpgmdndccklfigfhajenno
Free Weather Forecastchromedpdibkjjgbaadnnjhkmmnenkmbnhpobjno
Video Speed Controller - Video managerchromegaiceihehajjahakcglkhmdbbdclbnlfno
Unlock Discord - VPN Proxychromemlgbkfnjdmaoldgagamcnommbbnhfnhfno
Dark Theme - Dark Reader for Chromechromeeckokfcjbjbgjifpcbdmengnabecdakpno
Volume Max - Ultimate Sound Boosterchromemgbhdehiapbjamfgekfpebmhmnmcmemgno
Unblock TikTokchromecbajickflblmpjodnjoldpiicfmecmifno
Unlock YouTube VPNchromepdbfcnhlobhoahcamoefbfodpmklgmjmno
Color Picker, Eyedropper - Gecochromeeokjikchkppnkdipbiggnmlkahcdkikpno
Weatherchromeihbiedpeaicgipncdnnkikeehnjiddckno
Unlock TikTokedgejjdajogomggcjifnjgkpghcijgkbcjdino
Volume Booster - Increase your soundedgemmcnmppeeghenglmidpmjkaiamcacmgmno
Web Sound Equalizeredgeojdkklpgpacpicaobnhankbalkkgaafpno
Header Valueedgelodeighbngipjjedfelnboplhgediclpno
Flash Player - games emulatoredgehkjagicdaogfgdifaklcgajmgefjllmdno
Youtube Unblockededgegflkbgebojohihfnnplhbdakoipdbpdmno
SearchGPT - ChatGPT for Search Engineedgekpilmncnoafddjpnbhepaiilgkdcieafno
Unlock Discordedgecaibdnkmpnjhjdfnomfhijhmebigcelono

Indicators of compromise (1)

domainadmitclick.netC2 / URL exfil + redirect

Sources