Breaking Endpoint Anti-Ransomware: Going Browser Native
Nishant Sharma (Director of Threat Research · Zcaler), Vivek Ramachandran
BSidesSF 2026 · Day 2 · AMC Theatre 07
Overview
In an era where digital identities and critical data increasingly reside within the browser and cloud services, traditional endpoint security measures are facing a formidable new challenge. This talk, "Breaking Endpoint Anti-Ransomware: Going Browser Native," presented by Nishant Sharma, Director of Threat Research at Zscaler (formerly of Square X), illuminates a paradigm shift in ransomware attacks. Sharma meticulously details how malicious actors are circumventing conventional endpoint detection and response (EDR) systems by executing ransomware operations entirely within the browser environment, without ever touching the underlying operating system.
Key moments
- 0:00 Introduction to browser-native anti-ransomware concept
- 2:00 Why browser is the new endpoint for threats
- 3:50 Ransomware evolution and AI browser agent risks
- 6:00 Browser becoming the center point of cyberattacks
- 8:00 Overview of browser-native attack vectors like OAuth, SSO
Breaking Endpoint Anti-Ransomware: Going Browser Native
Speakers: Nishant Sharma, Director of Threat Research, Zscaler; Vivek Ramachandran
Conference: BSides SF
YouTube: https://www.youtube.com/watch?v=oaOUIKptddc
Overview
In an era where digital identities and critical data increasingly reside within the browser and cloud services, traditional endpoint security measures are facing a formidable new challenge. This talk, "Breaking Endpoint Anti-Ransomware: Going Browser Native," presented by Nishant Sharma, Director of Threat Research at Zscaler (formerly of Square X), illuminates a paradigm shift in ransomware attacks. Sharma meticulously details how malicious actors are circumventing conventional endpoint detection and response (EDR) systems by executing ransomware operations entirely within the browser environment, without ever touching the underlying operating system.
The core premise of the presentation is that the browser has evolved into the primary battleground for cybersecurity, housing not just web applications but also user identities, cloud-stored files, and increasingly, autonomous AI agents. This centralization of critical assets makes the browser an irresistible target for attackers seeking to bypass established endpoint defenses. Sharma's research highlights a concerning trend where sophisticated, scalable attacks leverage stolen tokens, abused OAuth consent grants, and malicious browser extensions to exfiltrate, encrypt, and delete data directly from cloud storage platforms, leaving traditional anti-ransomware solutions completely blind.
This talk is crucial for anyone involved in cybersecurity, from security architects and incident responders to everyday users. It provides a stark warning about the limitations of current endpoint-centric security models against these emerging browser-native threats. By demonstrating practical proof-of-concept attacks, Sharma not only exposes critical vulnerabilities in the current security landscape but also underscores the urgent need for a dedicated browser security posture that can detect and mitigate these stealthy, persistent, and highly damaging forms of ransomware.
Background
▶ Watch: Introduction to browser-native anti-ransomware concept (0:00)
The landscape of cyber threats has undergone significant transformations over the past decade, with ransomware standing out as one of the most persistent and financially devastating attack vectors. Nishant Sharma opens by tracing the evolution of ransomware, noting its rise to prominence around 2017 with large-scale incidents like WannaCry. Since then, ransomware has diversified, impacting critical infrastructure, healthcare, and countless organizations globally. The financial stakes have escalated dramatically, with the average ransom demand skyrocketing from $5,000 in 2018 to an astonishing $1 million by 2025. This escalating threat has spurred substantial investment in endpoint anti-ransomware capabilities, with nearly every major security vendor offering EDR solutions designed to detect and prevent malicious activity on the endpoint.
However, the very nature of computing is shifting, creating new blind spots for these established defenses. Sharma emphasizes that the modern computing paradigm is increasingly browser-centric. An estimated 80% of all cyber threats now originate or enter through the browser. User identities, critical applications, and sensitive files have migrated from local machines to cloud-based Software-as-a-Service (SaaS) platforms. The browser is no longer merely an internet access tool; it is a de facto operating system, a central hub where identity, data, and application logic converge. This trend is further amplified by the advent of powerful AI browsers and AI agents (such as Atlas, Comet, and integrations from Anthropic and OpenAI) that possess autonomous capabilities and significant control over browser functions. While these agents offer convenience, early versions, as Sharma's research showed, were highly susceptible to attacks that human users might now recognize, highlighting a new attack surface.
The evolution of attack vectors mirrors this shift. What began as basic phishing emails designed to steal credentials has progressed to more sophisticated techniques like QR phishing and OAuth consent grant attacks. These newer methods bypass the need for direct credential theft by tricking users into delegating broad permissions to malicious applications, all within the browser's legitimate framework. The critical insight shared by Sharma is that if a ransomware attack can achieve its objectives—denying access to files, exfiltrating data, and demanding ransom—without ever interacting with the endpoint's filesystem or processes, then traditional EDRs, which are designed to monitor these very activities, become irrelevant. The browser, therefore, emerges as the new "endpoint" for a new generation of ransomware.
Key Findings
▶ Watch: Why browser is the new endpoint for threats (2:00)
The presentation meticulously outlines several key findings that collectively paint a concerning picture of the evolving threat landscape and the vulnerabilities inherent in browser-centric operations:
- Browser as the Primary Attack Surface: The most significant finding is the assertion that the browser has become the central point of attack, effectively replacing the traditional endpoint as the primary target for sophisticated adversaries. With 80% of threats originating from the browser and critical assets like identity and files migrating to SaaS and cloud storage, the browser's security posture is paramount.
- Bypass of Traditional Endpoint Defenses: Browser-native ransomware operates entirely within the browser's context, leveraging cloud APIs and delegated access. This means that Endpoint Detection and Response (EDR) solutions and conventional anti-ransomware tools, which are designed to monitor file system activity, process execution, and network traffic on the local machine, are fundamentally blind to these attacks. The malicious actions occur in the cloud, orchestrated via browser-acquired tokens, rendering endpoint agents ineffective.
- Exploitation of OAuth Consent Grants: A core technical finding is the widespread vulnerability to OAuth consent grant attacks. Users are often tricked into granting excessive, persistent permissions (known as scopes) to malicious applications. These scopes can include highly sensitive actions like "read, compose, send, and permanently delete all of your email from Gmail" or "see, edit, create, and delete all of your Google Drive files." Once granted, these permissions provide attackers with persistent, legitimate access to cloud services, enabling data exfiltration, deletion, and ultimately, a browser-native ransomware scenario.
- Pervasiveness of Malicious Browser Extensions: Sharma highlights browser extensions as a significantly overlooked and dangerous vector. Research by Square X found that only 3% of an extension's code typically performs its claimed functionality, while the remaining 97% often engages in covert activities. These activities range from stealing credentials and tokens to tracking user behavior, injecting ads, and even exfiltrating browsing history. The automatic update mechanism of browser extensions means a benign extension can turn malicious overnight without user knowledge, often after being sold on underground marketplaces for as little as $3,000 for an extension with 50,000 users.
- Scalability and Persistence of Browser-Native Attacks: Unlike highly targeted endpoint attacks, browser-native ransomware leveraging OAuth tokens or malicious extensions is inherently scalable. A single malicious application or extension can be distributed to hundreds of thousands of users, and the delegated access remains persistent until manually revoked by the user. This automation allows attackers to monetize attacks against individual users, not just large enterprises, making it a lucrative venture even with smaller ransom demands.
- Vulnerability of AI Agents: Early iterations of AI agents and AI browsers (e.g., Comet) were found to be highly susceptible to these browser-native attacks, even basic phishing and consent grant mechanisms. While vendors are improving security, the increasing autonomy and control these agents have over browser functions introduce new attack surfaces that require continuous monitoring and protection.
These findings collectively underscore the urgent need for a paradigm shift in cybersecurity, moving beyond endpoint-centric defenses to embrace dedicated browser security solutions that can monitor, detect, and mitigate threats operating within the browser environment.
Technical Deep Dive
▶ Watch: Ransomware evolution and AI browser agent risks (3:50)
The technical core of the browser-native ransomware attack hinges on exploiting legitimate browser functionalities and user trust to gain unauthorized, persistent access to cloud-stored data. Sharma delves into several key attack vectors and the underlying mechanisms that enable this new form of ransomware.
Attack Vectors
- OAuth Consent Grant Attacks: This is arguably the most potent vector. OAuth (Open Authorization) is an open standard for access delegation, commonly used for "Login with Google," "Login with Facebook," etc. When a user logs into a third-party application using an OAuth provider, they are presented with a consent screen detailing the permissions (scopes) the application is requesting. Attackers craft malicious applications that request overly broad and dangerous scopes, such as:
read, compose, send, and permanently delete all of your email from Gmailsee, edit, create, and delete all of your Google Drive filesmanage your files in Dropbox
If a user, often due to lack of awareness or distraction, grants these permissions, the malicious application receives an access token that grants it persistent, legitimate access to the specified cloud service. This token can then be used to perform ransomware actions: exfiltrating files, deleting originals, and uploading ransom notes, all without touching the user's local machine. The attacker's control is persistent until the user manually revokes the consent in their Google, Microsoft, or other service settings.
- Malicious Browser Extensions: Browser extensions operate with significant privileges within the browser environment. Sharma's research revealed that the vast majority of code in many extensions (97%) is not related to their advertised function. These hidden functionalities can include:
- Credential and Token Theft: Directly capturing login credentials and session tokens as users interact with websites.
- Data Exfiltration: Collecting browsing history, sensitive information from web pages, and even tracking user activity across sites.
- Content Injection: Injecting malicious JavaScript, ads, or phishing elements into legitimate web pages.
The primary danger is the automatic update mechanism of extensions. A benign extension can be acquired by a malicious actor, updated with new, nefarious code, and automatically pushed to tens of thousands of users without their explicit consent or even knowledge. This creates a persistent backdoor that can then be leveraged for OAuth attacks, browser synjacking, or direct data manipulation.
- Browser Synjacking / Full-Screen Mode Attacks: This technique involves tricking a user into believing they are interacting with their local browser, when in reality, they are connected to a remote attacker-controlled machine, often via a full-screen mode that obscures the browser's address bar. The user inputs their credentials and even 2FA codes, believing they are logging into a legitimate service. The attacker captures these inputs, gaining full access to the user's account and potentially their session tokens. This method is effective because it leverages the user's implicit trust in the visual cues of their browser environment.
- SSO Hijacking: While mentioned broadly, this refers to various techniques that compromise Single Sign-On (SSO) sessions, often involving session token theft or manipulation. Combined with other browser-based attacks, an SSO hijack can grant an attacker broad access across an organization's cloud services.
- Rogue AI Agents and Plugins: The emergence of AI agents and browser plugins (including unsanctioned ones) introduces new avenues for control over browser functions. These agents, if compromised or designed maliciously, can interact with web pages, make decisions, and execute actions based on instructions, potentially leveraging their inherent browser access to facilitate ransomware activities or data exfiltration.
Attack Flow and Automation
The typical flow for a browser-native ransomware attack, as demonstrated, involves several stages:
- Initial Access / Lure:
- Phishing Emails: Crafting highly convincing emails (e.g., fake Chrome Store updates, urgent policy changes) to direct users to malicious websites.
- Malicious Extensions: Users installing seemingly benign extensions that are either malicious from the start or become so after an update.
- Social Engineering: Offering enticing services (free graphics tools, "free" ChatGPT access) that require "Login with Google."
- Token/Access Acquisition:
- OAuth Consent: Tricking users into granting broad permissions to a malicious app via an OAuth consent screen.
- Credential/Token Theft: Using malicious extensions or browser synjacking to directly steal session tokens or credentials, including 2FA.
- Ransomware Execution (Browser-Native):
- Once the attacker has a persistent access token (e.g., for Gmail, Google Drive, Dropbox), they can use the respective cloud service's APIs to:
- Exfiltrate Data: Download sensitive files from cloud storage.
- Delete Originals: Remove the original files from the victim's cloud storage.
- Upload Ransom Note: Replace the deleted files with a text file containing ransom demands.
- Password Reset Hijack (Email-based): If Gmail access is granted, the attacker can initiate password resets for other services (like Dropbox). They then intercept and delete the password reset emails from the victim's inbox before the user notices, effectively taking over the linked account.
Crucially, all these steps, from token acquisition to data manipulation and ransom note upload, can be fully automated. This automation allows attackers to operate at scale, targeting thousands of individual users simultaneously, making it a highly efficient and profitable endeavor even if individual ransom payments are smaller than those from corporate targets. The persistence of OAuth grants further ensures that access remains active until manually revoked by the user, providing a prolonged window for exploitation.
Demo / Proof of Concept
▶ Watch: Browser becoming the center point of cyberattacks (6:00)
Nishant Sharma presented two compelling demonstrations to illustrate the efficacy and stealth of browser-native ransomware, highlighting how these attacks bypass traditional endpoint security and leverage legitimate cloud service functionalities for malicious ends.
Demo 1: Gmail and Dropbox Ransomware via OAuth Consent
The first demonstration showcased a scenario where an attacker leverages an OAuth consent grant to gain control over a victim's Gmail account, subsequently using that access to compromise their Dropbox storage.
- Initial Lure: The victim receives a phishing email, which is a common entry point for such attacks. The email contains a link to a seemingly legitimate website. Sharma notes that in a real-world scenario, such a website would be meticulously crafted to appear trustworthy and relevant to the victim's interests, potentially informed by prior malicious extension activity tracking their browsing habits.
- OAuth Consent Request: Upon visiting the malicious website, the victim is prompted to "Login with Google." This initiates an OAuth flow, presenting a Google consent screen. Critically, this screen requests broad permissions: "read, compose, send, and permanently delete all of your email from Gmail." The speaker emphasizes that users often overlook these detailed permission requests, simply clicking "Allow."
- Persistent Gmail Access: Once the victim clicks "Allow," the attacker's malicious application receives a persistent access token with the granted Gmail scopes. The victim is then redirected to a benign-looking page, so they suspect nothing is amiss.
- Attacker's View and Automation: From the attacker's perspective, a custom UI (representing an automated backend process) now displays all emails from the compromised Gmail account. The attacker can filter these emails, specifically looking for password reset requests or notifications from cloud storage providers.
- Dropbox Compromise: The attacker initiates a password reset for the victim's Dropbox account. The password reset email is sent to the compromised Gmail address. Because the attacker's app has "permanently delete" permissions, they can intercept and delete this email before the victim sees it, effectively hiding their tracks.
- Data Exfiltration, Deletion, and Ransom Note: With the Dropbox password reset, the attacker gains full access to the victim's Dropbox. They then proceed to:
- Download all files from the victim's Dropbox (exfiltration).
- Delete the original files from Dropbox.
- Upload a ransom note file, demanding payment for the return of the data.
This demo powerfully illustrates how a single, seemingly innocuous click on an OAuth consent screen can lead to a complete compromise of critical cloud services, all without triggering any endpoint security alerts. The entire operation is "browser native," operating through web services and APIs.
Demo 2: Google Drive Ransomware via OAuth Scope
The second demonstration focused on a direct ransomware attack against Google Drive, again leveraging an OAuth consent grant, but with a different scope.
- Victim's Environment: The demo begins by showing the victim's machine, which has a Google Drive mounted (e.g., G drive) containing several files.
- Lure via Legitimate-Looking Service: The victim navigates to a seemingly legitimate online diagramming website. Many such services offer integration with cloud storage providers like Google Drive for convenient file saving and access.
- OAuth Consent for Google Drive: The website prompts the victim to "Login with Google" to save their work to Google Drive. The ensuing OAuth consent screen requests a highly dangerous scope: "see, edit, create, and delete all of your Google Drive files."
- Ignorant Consent: The speaker notes that early versions of AI browsers like Comet were particularly susceptible to this, not prompting users to carefully review permissions. In this demo, the user, being "ignorant," clicks "Allow."
- Automated Ransomware Execution: Immediately upon consent, the attacker's application, now armed with the Google Drive token and permissions, automatically proceeds to:
- Delete all files from the victim's Google Drive.
- Upload a ransom note to the empty Google Drive.
- Attacker's Control: The attacker's UI shows confirmation of the deleted files and the uploaded ransom note. The speaker reiterates that this entire process is automated and scalable, affecting not just Google Drive but any service that uses similar OAuth-based login (e.g., OneDrive).
Both demos underscore the critical role of user awareness regarding OAuth scopes and the need for robust security solutions that can intercept and analyze these browser-level interactions. The "persistent access" granted by OAuth tokens means attackers don't need to re-compromise the user, maintaining control until the user manually revokes the application's permissions.
Defensive Implications
▶ Watch: Overview of browser-native attack vectors like OAuth, SSO (8:00)
The emergence of browser-native ransomware necessitates a re-evaluation of current cybersecurity strategies. Traditional endpoint defenses are demonstrably insufficient, prompting a shift towards a more comprehensive browser security posture. Nishant Sharma outlines several key defensive implications:
- Enhanced User Education and Awareness: This remains the first line of defense. Users must be educated to:
- Scrutinize OAuth Consent Screens: Understand the specific permissions (scopes) requested by applications during "Login with Google" or similar processes. If an app requests excessive permissions for its stated function, it should be denied.
- Be Wary of Phishing and Social Engineering: Recognize the sophisticated lures used to direct them to malicious sites or encourage installation of harmful extensions.
- Understand Browser Extension Risks: Be cautious about installing extensions, review their permissions, and understand that even previously benign extensions can become malicious.
However, Sharma acknowledges the limitations of education alone. With over 100 documented browser threat vectors and the complexities of real-world multitasking (e.g., juggling 15 browser tabs), relying solely on human vigilance is unrealistic.
- Dedicated Browser Security Solutions: Given the limitations of human factors and endpoint-centric tools, the most robust defense lies in specialized browser security solutions. These solutions operate directly within or alongside the browser environment to provide real-time protection:
- Deployment Methods: These can be deployed as enhanced browser extensions, dedicated secure browsers, or as part of a security proxy infrastructure that intercepts and inspects browser traffic.
- Capabilities: They are designed to:
- Monitor Browser Activity: Observe everything the user sees and does within the browser.
- Scan for Malicious Elements: Detect malicious JavaScript, injected content, or suspicious activity in real-time.
- Intercept and Block: Prevent users from clicking on malicious links, granting dangerous OAuth scopes, or interacting with compromised extensions before damage occurs.
- Visibility into Rogue AI Agents: Provide oversight for unsanctioned AI agents or plugins that might attempt to control browser functions.
- Enterprise-Level Controls and Management: For organizations, additional layers of defense are crucial:
- Email Security Gateways (ESG): While not foolproof, ESGs can help filter out initial phishing emails that serve as the entry point for many browser-native attacks.
- Strict Extension Whitelisting/Blacklisting: Enterprises should manage and restrict the installation of browser extensions. However, this is challenging due to the dynamic nature of extensions (e.g., extensions changing hands, becoming malicious after updates) and the difficulty of maintaining a comprehensive whitelist for diverse user needs.
- Granular OAuth Scope Management: While complex, organizations should explore mechanisms to enforce minimum necessary permissions for applications using OAuth. This could involve group-based management or policies that flag or block requests for overly broad scopes.
- Just-in-Time Monitoring and Interception: This is critical for catching threats that bypass initial filters. Security solutions should provide real-time analysis and intervention capabilities within the browser session itself.
- Focus on Cloud Security Posture: Since the attacks target cloud-stored data via browser-acquired tokens, organizations must also strengthen their cloud security posture:
- Regular Audits of OAuth Grants: Users should be encouraged to regularly review and revoke unnecessary application permissions granted to their Google, Microsoft, and other cloud accounts.
- Cloud Access Security Brokers (CASBs): CASBs can provide visibility and control over data access in cloud applications, potentially detecting unusual activity or mass deletions.
- Data Backup and Recovery: Comprehensive, immutable backups of cloud data remain a fundamental defense against any form of ransomware.
In summary, defending against browser-native ransomware requires a multi-pronged approach that combines robust user education with advanced, dedicated browser security solutions and a strong cloud security posture. The emphasis must shift from purely endpoint-focused protection to a holistic strategy that secures the browser—the new center of digital life and the primary gateway for modern threats.
Key Takeaways
- The Browser is the New Endpoint: With identity, applications, and files migrating to cloud-based SaaS, the browser has become the primary attack surface, rendering traditional endpoint security (EDRs) ineffective against browser-native threats.
- OAuth Consent Attacks Grant Persistent, Powerful Access: Malicious applications can trick users into granting broad, persistent permissions (scopes) to their cloud services (e.g., Gmail, Google Drive, Dropbox), enabling data exfiltration, deletion, and ransom note uploads without touching the local machine.
- Malicious Browser Extensions are a Stealthy and Scalable Threat: Extensions can steal credentials, tokens, track activity, and inject content. Their automatic update mechanism means a benign extension can become malicious overnight, providing a persistent backdoor for attackers.
- Traditional Anti-Ransomware is Blind: Because browser-native ransomware operates entirely within the browser's context and leverages cloud APIs, it bypasses endpoint-centric defenses that monitor local file system or process activity.
- User Education is Crucial but Insufficient: While educating users about OAuth scopes and phishing is vital, the volume and sophistication of browser-based attack vectors, combined with real-world distractions, necessitate technical security solutions.
- Dedicated Browser Security is Essential: Effective defense requires specialized browser security solutions that can monitor, intercept, and block malicious activity in real-time within the browser environment, complementing existing endpoint and email security measures.
About the Speaker(s)
Nishant Sharma is a Director of Threat Research at Zscaler. Prior to joining Zscaler, he was part of Square X, a company focused on browser security, which was subsequently acquired by Zscaler. With over 10 years of experience in the cybersecurity field, Nishant has a strong background in cyber security education and has presented his research at multiple industry venues. His expertise lies in understanding evolving threat vectors, particularly those targeting the browser and cloud environments.
While Vivek Ramachandran is listed as a speaker for this talk, the provided transcript indicates that Nishant Sharma was the primary presenter.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Competent threat research walk-through on browser-native ransomware via OAuth abuse and malicious extensions, with live demos that land the core point cleanly. The attack concepts are real and worth communicating, but none of this is novel to anyone who's been paying attention to browser security research over the past few years — and the Zscaler acquisition of SquareX hangs over the defensive section like a billboard.
Heather Calloway (CISO) — WEAK
Technically coherent and the OAuth abuse angle is real, but this talk is a Zscaler acquisition pitch dressed as threat research. The defensive section lands on 'buy browser security' without giving operators, architects, or CISOs a usable decision path that doesn't route through the speaker's employer.