VMware and Microsoft warn about a continuing, widely spread Chromeloader malware campaign that has evolved into a more dangerous threat, with the drop of malicious browser extensions, malware node-WebKit and even ransomware in some cases.

Infections from Chromeloader increased in Q1 2022, with Red Canary researchers warning about the risks of the browser hijacker used for marketing affiliation and advertising fraud.
Then, the malware infected Chrome with a malicious extension that redirected user traffic to advertising sites to carry out click fraud and generate revenue for the threatening actors.
A few months later, Palo Alto Networks' Unit 42 observed that Chromeloader was evolving into an information-stealing system, attempting to snatch data stored in browsers while simultaneously maintaining its adware functions.
On Friday night, Microsoft warned of an “ongoing large-scale click fraud campaign” attributed to a threat actor tracked as DEV-0796 using Chromeloader to infect victims with various malware.

Today, VMware analysts published a technical report describing several Chromeloader variants used in August and this month, some of which drop much more powerful payloads.
New variants that drop malware
The malicious ChromeLoader software is delivered in ISO files distributed via malicious ads, browser redirects and YouTube video comments.
ISO files have become a popular method of distributing malware ever since Microsoft started blocking Office macros by default. Additionally, when you double-click an ISO in Windows 10 and later, it automatically mounts as a CDROM under a new drive letter, making it an effective way to distribute multiple malware files at once.

ChromeLoader ISOs usually contain four files, a ZIP file that contains the malware, an ICON file, a batch file (commonly called Resources.bat) that installs the malicious software and a Windows shortcut that launches the batch file.
As part of its research, VMware examined at least ten Chromeloader variants since the beginning of the year, with the most interesting appearing after August.

The first example is a program that mimics OpenSubtitles, a helper program that helps users locate subtitles for movies and TV shows. In this campaign, the threat actors moved away from their usual file “Resources.bat” and switched to one named “properties.bat”, which is used to install malicious software and create persistence by adding Registry keys.
Another notable case is “Flbmusic.exe”, which mimics the FLB Music player, features an Electron runtime and allows the malware to load additional modules for network communication and port monitoring.
For some variants, the attacks became a bit destructive, extracting ZipBombs that overload the system with a massive unpacking operation.
“As recently as late August, ZipBombs have been observed being dropped on infected systems. The ZipBomb is dropped with the initial infection in the file downloads . The user must double-click to execute the ZipBomb. Once executed, the malware destroys the user’s system by overloading it with data,” VMware’s report explains.
Even more worryingly, recent variants of Chromeloader have been observed deploying Enigma ransomware in an HTML file.
Enigma is an old ransomware strain that uses a JavaScript- based installer and an embedded executable so it can be launched directly from the default browser .
After encryption is complete, the “ .enigma ” filename extension is added to the files, while the ransomware drops a “ readme.txt ” file containing instructions for victims.

Adware should not be ignored
Because adware does not cause noticeable damage to victims' systems, aside from consuming some bandwidth, it is usually a threat that is ignored or downplayed by analysts.
However, any software that integrates into systems undetected is a candidate for more significant problems, as its creators may implement modifications that facilitate more aggressive monetization options.
While Chromeloader started out as adware, it is a perfect example of how threat actors are experimenting with more powerful payloads, exploring more profitable alternatives to ad fraud.
Information source: bleepingcomputer.com
