HomeSecurityCompromised sites spread malware via fake Chrome updates

Hacked sites spread malware via fake Chrome updates

Cybercriminals malicious scripts that create fake Google Chrome update notifications, ultimately exposing unsuspecting website visitors to malware.

See also: Balada Injector malware campaign: It has infected 1 million WordPress websites

websites

The attack began in November 2022, according to NTT security analyst Rintaro Koike , and escalated shortly thereafter at the end of February 2023. It now targets Japanese, Korean, and Spanish-speaking users – an expanded scope that is resulting in a worrying increase in activity.

To launch the attack, malicious JavaScript is injected into sites to execute scripts once the user visits them. If the visitor belongs to the target audience, these scripts will automatically download additional relevant content.

The malicious scripts are spread via the Pinata IPFS (InterPlanetary File System) service , rendering blacklisting and removal attempts futile by hiding the origin server hosting these files. When a user visits the site, the scripts simulate an error screen in Google Chrome, stating that a forced update is required to proceed further.

“occurred An error while updating Chrome automatically. Please install the update package manually later or wait for the next automatic update,” the fake Chrome error message states.

The malicious scripts will then secretly download a ZIP file titled “release.zip”, presenting it as something the user needs to install – for example, an update for Chrome.

See also: New Rilide malware targets Chromium-based browsers to steal cryptocurrency

However, this ZIP file contains a Monero that will exploit the device's CPU to generate cryptocurrency for the malicious actors.

malware
Hacked sites spread malware via fake Chrome updates

Upon startup, the malware copies itself to C:\Program Files\Google\Chrome as “updater.exe” and then executes a legitimate program in order to inject code into processes and initialize directly from memory.

According to VirusTotal, the malware leverages BYOVD (“Bring Your Own Vulnerable Driver”) to exploit a flaw in WinRing0x64.sys and gain SYSTEM privileges on device .

By scheduling tasks for itself and making changes to the registry, the miner bypasses Windows Defender to remain persistent.

Additionally, Windows Update can be blocked and security products' communication with their servers can be prevented by changing the IP addresses of these sources in the HOSTS file. This can prevent updates and security threat monitoring, potentially even disabling an antivirus system entirely.

After the miner completes all these steps, they can then log in to xmr.2miners[.]com and start mining Monero (XMR), a cryptocurrency with a particularly high level of anonymity protection.

As some of the spoofed sites are in Japanese, NTT has warned users to be aware that the scope of the threats now includes other languages. As a result, this campaign could soon become more widespread and damaging if it is not stopped quickly.

See also: CryptoClippy: New Clipper malware targets Portuguese crypto users

To ensure maximum security, never install software updates from third-party sites - always rely on the developer for such updates or use the automated update feature built into your program.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS