By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: New Malware Hits 300,000 Users with Rogue Chrome and Edge Extensions
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > New Malware Hits 300,000 Users with Rogue Chrome and Edge Extensions
Tech News

New Malware Hits 300,000 Users with Rogue Chrome and Edge Extensions

By Viral Trending Content 4 Min Read
Share
SHARE

Aug 10, 2024Ravie LakshmananBrowser Security / Online Fraud

Malware

An ongoing, widespread malware campaign has been observed installing rogue Google Chrome and Microsoft Edge extensions via a trojan distributed via fake websites masquerading as popular software.

“The trojan malware contains different deliverables ranging from simple adware extensions that hijack searches to more sophisticated malicious scripts that deliver local extensions to steal private data and execute various commands,” the ReasonLabs research team said in an analysis.

“This trojan malware, existing since 2021, originates from imitations of download websites with add-ons to online games and videos.”

Cybersecurity

The malware and the extensions have a combined reach of at least 300,000 users of Google Chrome and Microsoft Edge, indicating that the activity has a broad impact.

At the heart of the campaign is the use of malvertising to push lookalike websites promoting known software like Roblox FPS Unlocker, YouTube, VLC media player, Steam, or KeePass to trick users searching for these programs into downloading a trojan, which serves as a conduit for installing the browser extensions.

The digitally signed malicious installers register a scheduled task that, in turn, is configured to execute a PowerShell script responsible for downloading and executing the next-stage payload fetched from a remote server.

Malware

This includes modifying the Windows Registry to force the installation of extensions from Chrome Web Store and Microsoft Edge Add-ons that are capable of hijacking search queries on Google and Microsoft Bing and redirecting them through attacker-controlled servers.

“The extension cannot be disabled by the user, even with Developer Mode ‘ON,'” ReasonLabs said. “Newer versions of the script remove browser updates.”

It also launches a local extension that is downloaded directly from a command-and-control (C2) server, and comes with extensive capabilities to intercept all web requests and send them to the server, receive commands and encrypted scripts, and inject and load scripts into all pages.

On top of that, it hijacks search queries from Ask.com, Bing, and Google, and funnels them through its servers and then on to other search engines.

Cybersecurity

Users who are affected the malware attack are recommended to delete the scheduled task that reactivates the malware each day, remove the Registry keys, and delete the below files and folders from the system –

  • C:Windowssystem32Privacyblockerwindows.ps1
  • C:Windowssystem32Windowsupdater1.ps1
  • C:Windowssystem32WindowsUpdater1Script.ps1
  • C:Windowssystem32Optimizerwindows.ps1
  • C:Windowssystem32Printworkflowservice.ps1
  • C:Windowssystem32NvWinSearchOptimizer.ps1 – 2024 version
  • C:Windowssystem32kondserp_optimizer.ps1 – May 2024 version
  • C:WindowsInternalKernelGrid
  • C:WindowsInternalKernelGrid3
  • C:WindowsInternalKernelGrid4
  • C:WindowsShellServiceLog
  • C:windowsprivacyprotectorlog
  • C:WindowsNvOptimizerLog

This is not the first time similar campaigns have been observed in the wild. In December 2023, the cybersecurity company detailed another trojan installer delivered through torrents that installed malicious web extensions masquerading as VPN apps but are actually designed to run a “cashback activity hack.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

ATU and Vodafone Ireland secure €4.6 million EU fund to develop digital technologies for online apprenticeship courses?

Trust Wallet Chrome Extension Hack Drains $8.5M via Shai-Hulud Supply Chain Attack

The Best Over-the-Counter Sleep Aids (2025), Tested and Reviewed

Feliz Navidad, Bodega Hampers reviewed

Can AI Solve Homelessness in Ireland?

TAGGED: browser security, Cyber Security, Cyber Threat, Cybercrime, data theft, Internet, Malware, online fraud, phishing
Share This Article
Facebook Twitter Copy Link
Previous Article Jerry Jones feels no sense of urgency to sign All-Pro WR CeeDee Lamb to a long-term deal
Next Article Philippines Slams China’s “Unjustified, Illegal, Reckless” Actions Over Disputed Scarborough Shoal Reef
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Digital ID, CBDCs risk turning US into ‘surveillance state': US Rep
Crypto
Stars With New Year’s Eve Birthdays: Gabby Douglas & More Celebrities
Celebrity
15 Best Action Adventure Games of 2025
Gaming News
Littler: I have 'no regrets' about crowd comments at Worlds
Sports
Carolyn Petit’s Top 5 Games Of 2025
Gaming News
Bitmine Expands Ethereum Holdings: Adds 32,938 ETH And Stakes Nearly 119K ETH
Crypto
ATU and Vodafone Ireland secure €4.6 million EU fund to develop digital technologies for online apprenticeship courses?
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Digital ID, CBDCs risk turning US into ‘surveillance state': US Rep

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Digital ID, CBDCs risk turning US into ‘surveillance state': US Rep
January 1, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?