A new campaign of malicious Google ads, coinciding with the release of the Arc browser for Windows, is tricking people into downloading installers that infect them with malware payloads.
See also: Proactive detection and treatment of malware

Arc browser is a new web browser, featuring an innovative user interface design that sets it apart from traditional browsers. It was released in July 2023 for macOS and after receiving rave reviews from tech publications and users, its recent release on Windows was eagerly anticipated.
Cybercriminals target Arc browser with malicious Google ads
According to a report by Malwarebytes, cybercriminals prepared for the product's launch by creating malicious ads on Google Search to entice users looking to download the new web browser.
Google's ad platform has a major issue that allows threat actors to remove ads displaying legitimate URLs, which has been abused to target Amazon, Whales Market, WebEx, and Google's video platform, YouTube.
Malwarebytes found promoted results for the search terms “arc installer” and “arc browser windows” that display the correct URL for Arc. However, after clicking the ad, users are redirected to domains with typos that visually resemble the authentic website.
If you click the “Download” button, a trojanized setup file is retrieved from the MEGA, which downloads an additional malicious payload named “bootstrap.exe” from an external resource. The MEGA API is abused for command and control (C2) functions, sending and receiving operational instructions and data. The setup file retrieves a PNG file containing malicious code that compiles and drops the final payload, “JRWeb.exe”, to the victim’s disk.
See also: Hackers FIN7: Malicious ads to distribute NetSupport RAT
Malwarebytes also observed a separate infection chain involving the installer using a Python executable to inject code into msbuild.exe, which queries an external website to retrieve commands to execute.

Analysts suggest that the final payload in these attacks is an information stealer, although this has yet to be determined.
Due to the installation of Arc browser on the victim's computer and the malicious files running secretly in the background, it is unlikely that the victim will realize that they are now infected with malware.
Threat actors exploiting the hype surrounding the release of new software/games is nothing new, but it is still an effective method for distributing malware.
Users who wish to download software should skip all promoted results in Google Search, use ad blockers that hide these results, and bookmark official project websites for future use. Additionally, always check the authenticity of domains from which they are going to download installers, and always scan downloaded files with an up-to-date AV tool before running them.
See also: Google ad impersonates Whales Market and promotes malware
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What is malvertising?
Malvertising, or malicious advertising, is a form of online threat where attackers use advertisements to distribute malicious software, such as in the case of the Arc browser. These advertisements can appear on legitimate websites, creating an illusion of security for users. Malvertising advertisements can contain code that exploits vulnerabilities in the browser or in plug-ins, such as Flash or Java. When a user clicks on such an advertisement, they can be redirected to a website hosting malware or automatically download malware to their computer. Malvertising can affect any website that hosts ads, even the most popular and trusted ones.
Source: bleepingcomputer
