HomeSecurityChromeLoader: The new malware that modifies browser settings

ChromeLoader: The new malware that modifies browser settings

ChromeLoader ,a browser hijacker malware, was seen in multiple attacks this month, making browser hijacking a widespread threat.

ChromeLoader malware browser

ChromeLoader malware, as a browser hijacker, can modify the victim's browser settings to display search results that promote unwanted software, fake giveaways and surveys, as well as adult games and dating sites.

See also: SpiceJet flights affected by ransomware attack

Malware operators use malware to make money. How do they do this? They use an affiliate marketing system, traffic user to advertising sites.

There are many malware of this type that compromise browsers, but according to experts, ChromeLoader stands out for its persistence, volume, and infection path, which includes the “aggressive” use of PowerShell.

PowerShell abuse

researchers , who have been tracking ChromeLoader malware activity since February of this year, say that its operators are using a malicious ISO archive file to infect their victims.

The ISO is disguised as a cracked executable file for a game or commercial software. This means that in most cases, victims may download it themselves from torrents or malicious sites.

See also: BPFDoor malware: Exploits Solaris vulnerability to gain root privileges

Researchers have observed that attackers are also leveraging social media to reach users. Experts have identified Twitter posts promoting “cracked” Android and offering QR codes that lead to sites hosting malware.

When a person double-clicks the ISO file on Windows 10 or later, the ISO file will be mounted as a virtual CD-ROM drive. This ISO file contains an executable file that is used to run the ChromeLoader malware. The executable is supposedly a game crack or keygen and uses names like “CS_Installer.exe”.

Finally, after various processes, ChromeLoader executes and decodes a PowerShell command that retrieves a file from a remote resource and loads it as a extension that hijacks the browser and manipulates search engine results.

ChromeLoader also targets macOS

The operators of the ChromeLoader malware also target macOS, aiming to compromise both Chrome and Safari browser. The infection chain on macOS is similar, but instead of ISO, the threat actors use DMG (Apple Disk Image) files, as it is a more common format on Apple's operating system.

See also: Mozilla: Fixes zero-days exploited in Pwn2Own

Additionally, instead of the installer executable, the macOS variant uses an installer bash script that downloads and unzips the ChromeLoader extension to the “private/var/tmp” directory.

browser malware

“To maintain persistence, the macOS of the ChromeLoader malware will append a preference (`plist`) file to the `/Library/LaunchAgents` directory,” the Red Canary report explains.

“This ensures that whenever a user logs into a graphical session, the ChromeLoader Bash script can be run continuously“.

For more information about the ChromeLoader malware and how it works, see the Red Canary report

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS