HomeSecurityChaes banking trojan: Affects Chrome with malicious extensions

Chaes banking trojan: Affects Chrome with malicious extensions

A large-scale campaign involving over 800 compromised WordPressis spreading banking trojans targeting the credentials of Brazilian e-banking users. The trojan used is called “Chaes” and, according to researchers from Avast, has been actively spreading since late 2021.

Chaes

See also: Banking malware: The most dangerous trojans that have ever existed!

Although the security firm notified the Brazilian CERT, the malicious campaign continues, with hundreds of websites still at risk.

When the victim visits one of the compromised websites, a pop-up window appears asking them to install a fake Java Runtime.

The MSI installer contains three malicious JavaScript (install.js, sched.js, sucesso.js) that prepare the Python environment for the next-stage loader.

The sched.js script adds persistence by creating a scheduled task and a launch link, and sucesso.js is responsible for reporting the status to C2.

Meanwhile, the install.js script performs the following tasks:

See also: Log4j Log4Shell vulnerability used to install Dridex banking trojan

Checks for Internet connection (using google.com)

Creates the folder %APPDATA%\\\\extensions

Downloads password-protected files such as python32.rar/python64.rar and unrar.exe to this extensions folder

Writes the path of the newly created extensions folder to HKEY_CURRENT_USER\\Software\\Python\\Config\\Path

Runs some basic system profiles

Runs the unrar.exe command with the password specified as an argument to unpack python32.rar/python64.rar

It connects to the C2 and downloads 32bit and 64bit __init__.py along with two encrypted payloads. Each payload has a pseudo-random name.

banking trojan

See also: 300,000 Android users have downloaded these banking trojan malware apps

The Python loading chain unfolds in memory and involves loading multiple scripts, shellcodes, and Delphi DLLs until everything is in place for the execution of the final payload in a Python process.

The final stage is handled by install.js, which retrieves Chrome extensions and installs them on the victim's system. Finally, all extensions are launched with the appropriate arguments.

Avast says it has seen five different malicious Chrome browser extensions installed on the victim's devices, including:

  • Online
  • Mtps4
  • Chronolog
  • Chronodx
  • Chromes
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS