Privacy News Fake IDM extension for Chromium-based browser stealing account

worldless

Level 1
Thread author
Verified
Mar 28, 2017
21
In summary, the long time existed & known-as-fake IDM extension provided on Chrome store that steals login information has been recently discovered by the VCCorp's security team.
The stealed information consists of username + password, login cookies for many popular services e.g Facebook, Google, Yahoo as well as other commerical accounts e.g Paypal and banks.

According to this report, the rogue attack mostly targets to users in Vietnam where IDM is illigally installed on almost every PCs, which could also install the fake extension silently.
 
Last edited:

worldless

Level 1
Thread author
Verified
Mar 28, 2017
21
Actually I once installed the fake extention but I change most of important passwords once per month as habit.
After Firefox 54 released combos with FDM, I finally could use them as main browser and ditched Chrome + IDM & stuffs..
Reading the report somehow makes me feel lucky :D
 
Last edited:

jackuars

Level 28
Verified
Top Poster
Well-known
Jul 2, 2014
1,717
Being a freebie lover, I don't have to search the wild for cracked software or pay for one anymore :) Was an long-time user of IDM (cracked) in the past, then switched to EagleGet when I found that it does essentially everything what the paid software could do for free.

Now I've this new found love for freeware software's since it does pretty much everything I want without spending a dime. Thanks to all the selfless developers for their time and efforts :)
 

DJ Panda

Level 30
Verified
Top Poster
Well-known
Aug 30, 2015
1,928
Never used the software and no pirating for me. Its kind of amusing how some "security experts" I have read claim that pirating software doesn't get you infected..:p
 
  • Like
Reactions: _CyberGhosT_

mlnevese

Level 28
Verified
Top Poster
Well-known
May 3, 2015
1,741
Doesn't the desktop version come with the extension?

It does... and IDM's help page even has a small tutorial on how to add the extension for Chromium based browsers that are not Google Chrome. I currently use it on Opera.
 

worldless

Level 1
Thread author
Verified
Mar 28, 2017
21
IMO some info is misread.
The fake extension tricks user to think that installing it from Chrome store is necesssary, even with people who already had the licensed IDM (but not install the official extension yet or it was automatically removed by Chrome in some cases).
The cracked IDM may also uses this trick.

P/s: Why am I the only one voted Yes :D :oops:
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top