• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

TechNews

Technology breaking news

  • Home
  • Startups
  • Science
  • Cybersecurity
  • Review

This nasty browser-hijacking malware is becoming a serious threat

May 27, 2022 by www.techradar.com Leave a Comment

Audio player loading…

The distribution of the ChromeLoader malware (opens in new tab) has spiked in recent months, turning a relative nuisance into a full-blown threat.

Researchers from Red Canary have been tracking the malware for the past five months, and claim the threat has risen significantly.

According to the research, the attackers are targeting both Windows and macOS users, distributing the malware via torrent files masquerading as cracks for software and games.

They're also using social media sites, such as Twitter, to promote the torrent links, sharing QR codes leading to the sites that host the malware.

ChromeLoader malware

The goal is to have the victims download the files themselves. For Windows targets, the files come in an .ISO archive which, when mounted with a virtual CD-ROM drive, displays an executive file posing as a crack or a keygen. Researchers are saying that its most likely filename is "CS_Installer.exe".

Once the victim runs the file, it executes and decodes a PowerShell command that pulls an archive from the server , and loads it as an extension for the Google Chrome browser (opens in new tab) . After that, PowerShell removes the scheduled task, leaving no traces of its presence.

Read more

> How to beat a browser hijacker (opens in new tab) > Fake streaming sites were the biggest threat of the Tokyo Olympics (opens in new tab) > This WordPress vulnerability could let hackers hijack your entire site (opens in new tab)

The methodology for macOS is somewhat different; instead of an ISO, the attackers use DMG files, which are more common on the platform. It also swaps the installer executable for an installer bash script that downloads and decompresses the extension into “private/var/tmp”.

ChromeLoader is described as a browser hijacker that can tweak browser settings on the target endpoint (opens in new tab) , making it show modified search results. By showing fake giveaways, dating sites, or unwanted third-party software, the threat actors earn commission in affiliate programs.

What makes ChromeLoader stand out in a sea of similar browser hijackers is its persistence, volume and infection route, the researchers said.

  • Keep your browsers secure with the best antivirus software around (opens in new tab)
  • Malware on the Mac - Viruses, Spyware, Worms, and Other Digital Nasties Are Coming to the Mac
  • Do You Know What is Spyware?
  • Free Trojan Remover Software
This nasty browser-hijacking malware is becoming a serious threat have 398 words, post on www.techradar.com at May 27, 2022. This is cached page on TechNews. If you want remove this page, please contact us.

Filed Under: Computing hijacked safari browser, about browser hijackers, hijacked internet browser, 2019 malware threats, 5 malware threats, top malware threats 2018, top malware threats 2019, hijacking browser virus, hijack web browser, virus browser hijacker, virus browser hijack, browser malware, remove browser malware, browser malware scanner, browser malware remover, browser malware removal, secure browser malware

Primary Sidebar

RSS Recent Stories

  • Oil Group Mocks Biden on Gas Prices Tweet: Intern Needs Econ Class
  • Joe Biden on Independence Day: America Has ‘Come Up Short’
  • Highland Park Attack Occurred Despite Stringent Gun Controls
  • iPhone 14 might be weaker than expected – here’s why
  • New stats show how much of your job really is a waste of time
  • Apple Watch 8 sounds more likely to get anticipated feature – but Watch SE 2 may not
  • Netflix cancels yet another animated show after one season
  • L’iPhone 14 serait moins puissant que prévu – voici pourquoi
  • Formula One driver survives horrific crash thanks to halo cockpit requirement
  • Opinion: We are thinking about AR/VR wrong

Sponsored Links

  • Major crash led to suspension of its Tesla Model 3 by taxi company
  • After Tesla, SpaceX workers come forward to speak on sexual harassment
  • Wi-Fi range extender to strengthen network coverage and internet speeds
  • apple: How to capture screenshot on Apple iPhone just by tapping back panel
  • EU Parliament backs tough new rules to rein in US tech giants
  • Carville: ‘Strap in People’ — January 6 Probe Will Expose Trump Was Behind a ‘Massive Criminal Act’
  • Warren: SCOTUS ‘Has Lost the Respect of the American People’ — We Need More Justices
  • Summers: Combatting Inflation Will ‘Require Substantially More’ Than What Fed Is Doing
  • Bratton: Lax District Attorneys, ‘Most of Them Funded by George Soros’ ‘Are Destroying the Criminal Justice System’
  • WATCH: Sheriff’s Deputies in Maryland Rescue Woman from Frigid Waters
Copyright © 2022 TechNews. Power by Wordpress.
Home - About Us - Contact Us - Disclaimers - DMCA - Privacy Policy - Submit your story