typetechniqueconfidencehighcreated2026-08-08updated2026-08-08browser-extensionsideloadcrx3persistencedefense-evasiondotnet

browser-extension-sideload-crx3

Malicious browser extension installation by building a valid CRX3 package from embedded resources, computing the extension ID from a public RSA key, writing extension policy registry entries, and installing via Chrome UI automation or fallback methods. Enables persistent access to browser internals even if the main malware process is terminated.

Technique Details

  • Extension building: BuildExtensionFiles, PackCrx3, PackAndRegisterCrx construct a CRX3 with embedded JS background script ^[strings.txt]
  • Extension ID derivation: CalcExtensionId computes the 32-char Chrome extension ID from the SHA-256 of the DER-encoded RSA public key ^[strings.txt]
  • Policy registration: WriteExtensionPolicy, WriteExternalExtension add registry entries under HKLM\Software\Policies\Google\Chrome\ExtensionInstallForcelist ^[strings.txt]
  • UI automation fallback: TryInstallExtensionViaUI, DoInstallExtensionViaUI use UIAutomation to click through Chrome's extension-install dialog if policy registration fails ^[strings.txt]

Cross-References