I found this post interesting for a few reasons: - the install vector for the malicious browser extension is pretty neat, and - the "customer id" that appears in multiple places, including a URL, appe
I found this post interesting for a few reasons: - the install vector for the malicious browser extension is pretty neat, and - the "customer id" that appears in multiple places, including a URL, appears to be a version 1 UUID, and Unfurl can extract the embedded timestamp (potentially useful for further analyzing the campaign) Unfurl on the download URL: https:// hindsig.ht/unfurl/?url=hxxps:/ /v