logo

Lucky_Cat__2021__proofpoint.com-TA413_Leverages_New_FriarFox_Browser_Extension_to_Target_the_Gmail_Accounts_of_Global_Tibetan_Organiz.pdf

ID: 80907d37-3447-4fda-9662-42d3b6de7114

STIX ID: report--80907d37-3447-4fda-9662-42d3b6de7114

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2021-02-26

Last Modified Date: 2021-02-26

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
TA413, an actor aligned with Chinese state interests, used phishing and watering-hole lures to deliver a malicious Firefox extension called FriarFox — a modified Gmail Notifier — to target Gmail accounts of Tibetan organizations; FriarFox granted broad Gmail and browser permissions and retrieved the Scanbox reconnaissance framework from actor-controlled domains for data collection and exfiltration, with multiple IOCs and infrastructure links to prior TA413 campaigns provided.