Cybercriminals malicious scripts that create fake Google Chrome update notifications, ultimately exposing unsuspecting website visitors to malware.
See also: Balada Injector malware campaign: It has infected 1 million WordPress websites

The attack began in November 2022, according to NTT security analyst Rintaro Koike , and escalated shortly thereafter at the end of February 2023. It now targets Japanese, Korean, and Spanish-speaking users – an expanded scope that is resulting in a worrying increase in activity.
To launch the attack, malicious JavaScript is injected into sites to execute scripts once the user visits them. If the visitor belongs to the target audience, these scripts will automatically download additional relevant content.
The malicious scripts are spread via the Pinata IPFS (InterPlanetary File System) service , rendering blacklisting and removal attempts futile by hiding the origin server hosting these files. When a user visits the site, the scripts simulate an error screen in Google Chrome, stating that a forced update is required to proceed further.
“occurred An error while updating Chrome automatically. Please install the update package manually later or wait for the next automatic update,” the fake Chrome error message states.
The malicious scripts will then secretly download a ZIP file titled “release.zip”, presenting it as something the user needs to install – for example, an update for Chrome.
See also: New Rilide malware targets Chromium-based browsers to steal cryptocurrency
However, this ZIP file contains a Monero that will exploit the device's CPU to generate cryptocurrency for the malicious actors.

Upon startup, the malware copies itself to C:\Program Files\Google\Chrome as “updater.exe” and then executes a legitimate program in order to inject code into processes and initialize directly from memory.
According to VirusTotal, the malware leverages BYOVD (“Bring Your Own Vulnerable Driver”) to exploit a flaw in WinRing0x64.sys and gain SYSTEM privileges on device .
By scheduling tasks for itself and making changes to the registry, the miner bypasses Windows Defender to remain persistent.
Additionally, Windows Update can be blocked and security products' communication with their servers can be prevented by changing the IP addresses of these sources in the HOSTS file. This can prevent updates and security threat monitoring, potentially even disabling an antivirus system entirely.
After the miner completes all these steps, they can then log in to xmr.2miners[.]com and start mining Monero (XMR), a cryptocurrency with a particularly high level of anonymity protection.
As some of the spoofed sites are in Japanese, NTT has warned users to be aware that the scope of the threats now includes other languages. As a result, this campaign could soon become more widespread and damaging if it is not stopped quickly.
See also: CryptoClippy: New Clipper malware targets Portuguese crypto users
To ensure maximum security, never install software updates from third-party sites - always rely on the developer for such updates or use the automated update feature built into your program.
