Fake Google Chrome Installer Steals Banking Details

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,379
Information Week said:
Beware fake Chrome installers for Windows.

A file named "ChromeSetup.exe" is being offered for download on various websites, and the link to the file appears to be legitimately hosted on Facebook and Google domains. In reality, the software won't install Google's Chrome browser, but an information-stealing Trojan application known as Banker, according to antivirus vendor Trend Micro.

Once the malware--which appears to be targeting Latin American users, especially in Brazil and Peru--is executed, it relays the IP address and operating system version to one of two command-and-control (C&C) servers, then downloads a configuration file. After that, whenever a user of the infected PC visits one of a number of banking websites, the malware intercepts the HTTP request, redirects the user to a fake banking page, and also pops up a dialog box informing the user that new security software will be installed.

In fact, the malware has been designed uninstall GbPlugin, which is "software that protects Brazilian bank customers when performing online banking transactions," said Trend Micro security researcher Brian Cayanan in a blog post. "It does this through the aid of gb_catchme.exe--a legitimate tool from GMER called Catchme, which was originally intended to uninstall malicious software. The bad guys, in this case, are using the tool for their malicious agendas."

Read more: http://www.informationweek.com/news/security/vulnerabilities/240000575
 

McLovin

Level 78
Verified
Honorary Member
Malware Hunter
Apr 17, 2011
9,228
How can you not tell that it's a fake Google Chrome installer. Mind you there are a lot of people out there that fall for a lot of things.
 

McLovin

Level 78
Verified
Honorary Member
Malware Hunter
Apr 17, 2011
9,228
Stonecold said:
Install Only from Homesite or sites like softpedia,cnet.

Yes, install and download from sites that have a very high reputation or have very good reviews.
 
D

Deleted member 178

McLovin said:
Stonecold said:
Install Only from Homesite or sites like softpedia,cnet.

Yes, install and download from sites that have a very high reputation or have very good reviews.

or check the hashes if you are not sure.
 

Spirit

Level 2
May 17, 2012
1,832
umbrapolaris said:
McLovin said:
Stonecold said:
Install Only from Homesite or sites like softpedia,cnet.

Yes, install and download from sites that have a very high reputation or have very good reviews.

or check the hashes if you are not sure.
+1 This is the best way to check original and unbroken installer for every software
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top