Industry News

Fake Microsoft Authenticator extension discovered in Chrome Store

I hope you’re being cautious if you’re installing extensions from the Chrome Web Store for your browser and care about your online security.

Because it’s reported that a bogus Chrome add-on purporting to be “Microsoft Authenticator” successfully managed to sneak its way in, and duped hundreds of people into downloading it.

As GHacks reports, an extension using both the name and branding of the legitimate Microsoft Authenticator app was discovered the browser add-on marketplace and managed to accrue a three out of five star rating.

According to the report, the fake Microsoft Authenticator extension was made available on April 23 this year after failing to be spotted by Google’s security systems and has reached 448 users.

Close inspection of the extension’s entry in the Chrome Web Store would, in an ideal world, have raised suspicions amongst potential downloaders: the add-on claimed to have been uploaded by “Extensions” rather than the “Microsoft Corporation” you would normally expect, and contact details pointed to Gmail rather than Microsoft’s domain.

Glancing at reviews of the extensions should also have raised alarm, as some of them clearly warned potential users of the danger, whereas other reviews (presumably fake) were brimming with suspicious praise.

Finally, Microsoft’s own webpages about its Authenticator product make clear that it is not available as a browser extension, but as an Android and iOS smartphone app.

If you were unfortunate enough to add the fake extension to your Chrome browser, GHacks described how you would be disappointed by its functionality:

The Microsoft Authenticator application cannot be used to authenticate Microsoft account sign-ins or any other sign-in for the matter. It displays a basic page with the option to “run Microsoft Authenticator”. A click on the button opens a Polish webpage that redirects to another webpage automatically asking for a sign-in or the creation of an account.

Clearly it was an extension not to be trusted, and it’s good to know that it has since been pulled from the Chrome Web Store by Google. But I wonder how many of those 400+ users might have unwittingly shared sensitive information in the meantime, not knowing that they had been duped.

It’s good that users are becoming more clued-up about the value additional levels of authentication can bring to their online security, but make sure not to be so keen to harden your defenses that you are fooled into installing fake software.

About the author

Graham CLULEY

Graham Cluley is an award-winning security blogger, researcher and public speaker. He has been working in the computer security industry since the early 1990s, having been employed by companies such as Sophos, McAfee and Dr Solomon's. He has given talks about computer security for some of the world's largest companies, worked with law enforcement agencies on investigations into hacking groups, and regularly appears on TV and radio explaining computer security threats.

Graham Cluley was inducted into the InfoSecurity Europe Hall of Fame in 2011, and was given an honorary mention in the "10 Greatest Britons in IT History" for his contribution as a leading authority in internet security.