A large-scale campaign involving over 800 compromised WordPressis spreading banking trojans targeting the credentials of Brazilian e-banking users. The trojan used is called “Chaes” and, according to researchers from Avast, has been actively spreading since late 2021.

See also: Banking malware: The most dangerous trojans that have ever existed!
Although the security firm notified the Brazilian CERT, the malicious campaign continues, with hundreds of websites still at risk.
When the victim visits one of the compromised websites, a pop-up window appears asking them to install a fake Java Runtime.
The MSI installer contains three malicious JavaScript (install.js, sched.js, sucesso.js) that prepare the Python environment for the next-stage loader.
The sched.js script adds persistence by creating a scheduled task and a launch link, and sucesso.js is responsible for reporting the status to C2.
Meanwhile, the install.js script performs the following tasks:
See also: Log4j Log4Shell vulnerability used to install Dridex banking trojan
Checks for Internet connection (using google.com)
Creates the folder %APPDATA%\\\\extensions
Downloads password-protected files such as python32.rar/python64.rar and unrar.exe to this extensions folder
Writes the path of the newly created extensions folder to HKEY_CURRENT_USER\\Software\\Python\\Config\\Path
Runs some basic system profiles
Runs the unrar.exe command with the password specified as an argument to unpack python32.rar/python64.rar
It connects to the C2 and downloads 32bit and 64bit __init__.py along with two encrypted payloads. Each payload has a pseudo-random name.

See also: 300,000 Android users have downloaded these banking trojan malware apps
The Python loading chain unfolds in memory and involves loading multiple scripts, shellcodes, and Delphi DLLs until everything is in place for the execution of the final payload in a Python process.
The final stage is handled by install.js, which retrieves Chrome extensions and installs them on the victim's system. Finally, all extensions are launched with the appropriate arguments.
Avast says it has seen five different malicious Chrome browser extensions installed on the victim's devices, including:
- Online
- Mtps4
- Chronolog
- Chronodx
- Chromes
