Lucky_Cat__2021__proofpoint.com-TA413_Leverages_New_FriarFox_Browser_Extension_to_Target_the_Gmail_Accounts_of_Global_Tibetan_Organiz.pdf
ID: 80907d37-3447-4fda-9662-42d3b6de7114
STIX ID: report--80907d37-3447-4fda-9662-42d3b6de7114
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2021-02-26
Last Modified Date: 2021-02-26
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
TA413, an actor aligned with Chinese state interests, used phishing and watering-hole lures to deliver a malicious Firefox extension called FriarFox — a modified Gmail Notifier — to target Gmail accounts of Tibetan organizations; FriarFox granted broad Gmail and browser permissions and retrieved the Scanbox reconnaissance framework from actor-controlled domains for data collection and exfiltration, with multiple IOCs and infrastructure links to prior TA413 campaigns provided.
