ADD ANI AS A TRUSTED SOURCE
googleads
ANI Logo
Menu
Business

SquareX Discloses Browser-Native Ransomware that Puts Millions at Risk

Palo Alto (California) [US], March 29: From WannaCry to the MGM Resorts Hack, ransomware remains one of the most damaging cyberthreats to plague enterprises. Chainalysis estimates that corporations spend nearly $1 billion dollars on ransom each year, but the greater cost often comes from the reputational damage and operational disruption caused by the attack.

ANI Mar 29, 2025 12:55 IST googleads

SquareX Discloses Browser-Native Ransomware that Puts Millions at Risk

India PR Distribution
Palo Alto (California) [US], March 29: From WannaCry to the MGM Resorts Hack, ransomware remains one of the most damaging cyberthreats to plague enterprises. Chainalysis estimates that corporations spend nearly $1 billion dollars on ransom each year, but the greater cost often comes from the reputational damage and operational disruption caused by the attack.
Ransomware attacks typically involve tricking victims into downloading and installing the ransomware, which copies, encrypts and/or deletes critical data on the device, only to be restored upon the ransom payment. Traditionally, the primary target of ransomware has been the victim's device. However, thanks to the proliferation of the cloud and SaaS services, the device no longer holds the keys to the kingdom. Instead, the browser has become the primary way through which employees conduct work and interact with the internet. In other words, the browser is becoming the new endpoint.
SquareX has been disclosing major browser vulnerabilities like Polymorphic Extensions and Browser Syncjacking, and is now issuing a strong warning on the emergence of browser-native ransomware. SquareX's founder, Vivek Ramachandran cautions, "With the recent surge in browser-based identity attacks like the one we saw with the Chrome Store OAuth attack, we are beginning to see evidence of the 'ingredients' of browser-native ransomwares being used by adversaries. It is only a matter of time before one smart attacker figures out how to put all the pieces together. While EDRs and Anti-Viruses have played an unquestionably vital role in defending against traditional ransomware, the future of ransomware will no longer involve file downloads, making a browser-native solution a necessity to combat browser-native ransomwares."
Unlike traditional ransomware, browser-native ransomware requires no file download, rendering them completely undetectable by endpoint security solutions. Rather, this attack targets the victim's digital identity, taking advantage of the widespread shift toward cloud-based enterprise storage and the fact that browser-based authentication is the primary gateway to accessing these resources. In the case studies demonstrated by SquareX, these attacks leverage AI agents to automate the majority of the attack sequence, requiring minimal social engineering and interference from the attacker.
One potential scenario involves social engineering a user into granting a fake productivity tool access to their email, through which it can identify all the SaaS applications the victim is registered with. It can then systematically reset the password of these apps with AI agents, logging the users out on their own and holding enterprise data stored on these applications hostage.
Similarly, the attacker can also target file sharing services like GoogleDrive, Dropbox and OneDrive, using the victim's identity to copy out and delete all files stored under their account. Critically, attackers can also gain access to all shared drives, including those shared by colleagues, customers and other third parties. This significantly expands the attack surface of browser-native ransomware - where the impact of most traditional ransomware is confined to a single device, all it takes is one employee's mistake for attackers to gain full access to enterprise wide resources.
As less and less files are being downloaded, it is inevitable for attackers to follow where work and valuable data is being created and stored. As browsers become the new endpoint, it is crucial for enterprises to reconsider their browser security strategy - just as EDRs were critical to defend against file-based ransomware, a browser-native solution with a deep understanding of client-side application layer identity attacks will become essential in combating the next generation of ransomware attacks.
To learn more about this security research, visit https://sqrx.com/browser-native-ransomware
About SquareX:
SquareX's industry-first Browser Detection and Response (BDR) solution helps organizations detect, mitigate and threat-hunt client-side web attacks happening against their users in real time. In addition to browser ransomware, SquareX also protects against various browser threats including identity attacks, malicious extensions, advanced spearphishing, GenAI DLP and insider threats.
The browser-native ransomware disclosure is part of the Year of Browser Bugs project. Every month, SquareX's research team releases a major web attack that focuses on architectural limitations of the browser and incumbent security solutions. Previously disclosed attacks include Browser Syncjacking and Polymorphic Extensions.
To learn more about SquareX's BDR, contact us at founder@sqrx.com. For press enquiries on this disclosure or the Year of Browser Bugs, email us at junice@sqrx.com.
(ADVERTORIAL DISCLAIMER: The above press release has been provided by India PR Distribution. ANI will not be responsible in any way for the content of the same)

Get the App

What to Read Next

Business

Piyush Goyal meets global industry leaders to deepen trade ties

Piyush Goyal meets global industry leaders to deepen trade ties

The meetings were inclined towards bolstering India's manufacturing capabilities and deepening its integration into global supply chains. The discussions focused on expanding investment partnerships and enhancing India's role as a critical hub in the Indo-Pacific region.

Read More
Business

India market "relatively resilient" compared to its Asian peers

India market

The deepening conflict in West Asia has placed the Indian economy and the broader Asian region in the "eye of the storm," as supply chain disruptions and surging energy costs threaten to trigger a significant negative growth shock.

Read More
Business

Adani Foundation to connect 10 lakh women nationwide

Adani Foundation to connect 10 lakh women nationwide

The Adani Foundation, today, declared that in the next one year, it will connect one lakh women in Maharashtra with the Swabhimaan initiative. For the future, Adani Foundation has announced to connect 10 lakh women in India with the same initiative and make them strong.

Read More
Business

Govt Urges Citizens to Avoid Panic Booking

Govt Urges Citizens to Avoid Panic Booking

Amid global energy disruptions following the closure of the Strait of Hormuz, the government has assured that the domestic supply of LPG, petrol, diesel, kerosene, and natural gas remains stable, while citizens are urged to avoid panic booking and conserve fuel, said Sujata Sharma, Joint Secretary of the Ministry of Petroleum and Natural Gas, today.

Read More
Business

India Emerging as Stable Investment Anchor in Turbulent Global

India Emerging as Stable Investment Anchor in Turbulent Global

Mumbai (Maharashtra) [India], March 12: As military conflict in West Asia disrupts energy supplies through the Strait of Hormuz and global liquidity tightens, leading investors, policymakers and capital markets leaders gathered at IGF Mumbai 2026: Catalysing Capital to assess India's position in an increasingly fragmented global economy.

Read More
Business

India pushes for green ship recycling, euro-compliant yards

India pushes for green ship recycling, euro-compliant yards

India is rapidly expanding its ship recycling sector and upgrading shipbreaking yards to meet European environmental standards, as part of a broader effort to strengthen its maritime industry and reduce logistics costs, Sushant Kumar Purohit, Chairperson of VO Chidambaranar Port Authority, said today.

Read More
Business

Sarbabharatiya Sangeet O Sanskriti Parishad Convenes 48th Annual

Sarbabharatiya Sangeet O Sanskriti Parishad Convenes 48th Annual

Kolkata (West Bengal) [India], March 12: Sarbabharatiya Sangeet O Sanskriti Parishad officially commenced its 48th Annual Convocation yesterday, March 11, at the historic Mahajati Sadan, Kolkata. The three-day event, running from March 11 to 13, celebrates the institution's legacy of cultural service and its mission to bridge traditional heritage with a modernized future.

Read More
Business

Indian envoy in Shanghai meets Ant Group top official

Indian envoy in Shanghai meets Ant Group top official

Consulate General of India in Shanghai Pratik Mathur on Thursday met Carrie Suen, Vice President and Head of Global Affairs and Strategic Development of Ant Group.

Read More
Business

Nandita Desai Unveils a Unique Painting Exhibition on Vintage

Nandita Desai Unveils a Unique Painting Exhibition on Vintage

New Delhi [India], March 12: There is something quietly powerful about a window... It neither confines nor escapes. It simply allows us to look, to pause, to breathe between inner and outer worlds. In The Painted Window, multi-award-winning contemporary artist Nandita Desai turns this everyday architectural element into the soul of her fifth solo exhibition, transforming vintage and handcrafted windows into luminous works of art. Running from 16th to 21st March 2026 at the Kamalnayan Bajaj Art Gallery, Nariman Point, Mumbai, the exhibition brings together 50 artworks - windows that look outward at the world, and inward at memory and quiet reflection.

Read More
Business

AdvantageClub.ai Celebrates 100 Global Women HR Leaders Driving

AdvantageClub.ai Celebrates 100 Global Women HR Leaders Driving

Gurugram (Haryana) [India], March 12: AdvantageClub.ai, a global AI-powered employee rewards, recognition and wellbeing platform, has unveiled the winners of the Most Admired Women Awards (MAW) 2026, honouring 100 outstanding women HR leaders who are driving transformation across the global workplace landscape.

Read More
Home About Us Our Products Advertise Contact Us Terms & Condition Privacy Policy

Copyright © aninews.in | All Rights Reserved.