Google Chrome extension named Desbloquear Contedo targeted users of Brazilian online banking services. Kaspersky Lab products detect the extension as HEUR:Trojan-Banker.Script. The extension uses the WebSocket protocol for data communication, making it possible to exchange messages with the C&C server in real time. This means the extension starts acting as a proxy server to which the extension redirects traffic when the victim visits the site of a Brazilian bank. This is a man-in-the-middle attack.”]
Source: https://securelist.com/a-mitm-extension-for-chrome/86057/

