Researchers at Zimperium zLabs discovered a malicious browser extension, dubbed Cloud9, that can steal users' private and sensitive information, and take complete control of the victim's device.After all, it's while you're browsing the web that you're more likely to input highly sought after credentials, including your bank passwords and other sensitive information.Cloud9 can do the following:- Track your keystrokes (i.e., keylogging) to steal your bank passwords, credit card info and more- Steal your copy-and-paste data (i.e., Clipboard)- Steal your cookies to compromise user sessions- Use your browser and computer resources to mine cryptocurrencies- Take control of your device by executing malicious code- Perform DDoS attacks from your PC- Inject pop ups and adsAlthough Cloud9 is a malicious browser plugin, the Zimperium zLabs team said that they didn't find it on any official browser extension store (e.g.Instead, more often than not, researchers discovered Cloud9 masquerading as an Adobe Flash Player update on malicious websites.Zimperium said that browsers are susceptible and vulnerable to Cloud9 because traditional endpoint security solutions are "not monitoring this vector of attack," but as long as you're not side-loading browser extensions and fraudulent executables from malicious websites, Cloud9 should remain a distant threat."