Malicious Chrome Extensions (Cyberhaven) - Threat Campaign Update
Incident Report for Rapid Response Status Page
Resolved
Dear customers,

Following our latest update, we continued with the threat-focused research and hunting efforts, further evaluating the threat and looking for potential hits in your organizational infrastructures.

AXON reports have been published for AXON customers, including:

- New Indicators of compromise
- Relevant hits that require your attention (both full list and summarized view)
- Link to a GitHub repository with a list of all relevant IOCs and threat hunting queries

Please feel free to reach out in case of any follow-up questions.

Sincerely,
Team AXON.
Posted Jan 02, 2025 - 15:10 UTC
Identified
Dear Customers,

Team AXON is continuing to investigate the Cyberhaven incident and has identified additional malicious chrome extensions. An updated AXON report outlining the new findings will be uploaded as soon as we conclude the investigation. If any new hits are identified in your environment you'll be notified in the updated AXON report.

Please feel free to reach out in case of any follow-up questions.

Sincerely,
Team AXON.
Posted Jan 01, 2025 - 10:14 UTC
This incident affected: Rapid Response.