Malware News Malware force-installs Chrome extensions on 300,000 browsers, patches DLLs

Gandalf_The_Grey

Level 82
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
7,189
An ongoing and widespread malware campaign force-installed malicious Google Chrome and Microsoft Edge browser extensions in over 300,000 browsers, modifying the browser's executables to hijack homepages and steal browsing history.

The installer and extensions, which are usually undetected by antivirus tools, are designed to steal data and execute commands on infected devices.

The campaign was discovered by researchers at ReasonLabs who warn that the threat actors behind it employ diverse malvertising themes to achieve initial infection.
ReasonLabs says the infection starts with the victims downloading software installers from fake sites promoted by malvertising in Google search results.

This malware campaign uses baits such as a Roblox FPS Unlocker, TikTok Video Downloader, YouTube downloader, VLC video player, Dolphin Emulator, and KeePass password manager.

The downloaded installers are digitally signed by 'Tommy Tech LTD' and successfully evade detection by all AV engines on VirusTotal at the time of its analysis by ReasonLabs.
 

Divine_Barakah

Level 33
Verified
Top Poster
Well-known
May 10, 2019
2,289
I hate to call these victims idiots, but users should download apps only from trusted sources.
I found a great way to install software without heading to each app's website. I created a Softpedia account and added the apps I am using to my Watchlist. Whenever an app receives an update, I get notified via email. I head to Softpedia which gives direct links to download the apps from their official sources.

An example of Softpedia email notifications
Hello,

This is a quick message to let you know that "Internet Download Manager
(IDM)" has been updated on our website to version "6.42 Build 19".

A link to the program's page is included below for your convenience:
https://www.softpedia.com/get/Internet/Download-Managers/Internet-Download-Manager.shtml

--
Sincerely,
The Softpedia Team

http://www.softpedia.com/

Note: You are receiving this update notification because this
application is part of your Softpedia account's watchlist and the email
notifications option is enabled.

If you do not wish to receive emails for this program, please log on to
your Softpedia account and remove the corresponding subscription from
your watchlist.

Alternatively, you can stop receiving emails of this type by unchecking
the "Update notifications via email" option. You will still be able to
get updates through your personal RSS feed you can find in the same area
of the account.
 
F

ForgottenSeer 114834

I found a great way to install software without heading to each app's website. I created a Softpedia account and added the apps I am using to my Watchlist. Whenever an app receives an update, I get notified via email. I head to Softpedia which gives direct links to download the apps from their official sources.

An example of Softpedia email notifications
This method carries risks. To ensure safety and reliability, download exclusively from official channels. Avoid third-party applications/websites.
 

Divine_Barakah

Level 33
Verified
Top Poster
Well-known
May 10, 2019
2,289
This method carries risks. To ensure safety and reliability, download exclusively from official channels. Avoid third-party applications/websites.
The links in Softpedia are direct links to official websites. I never had any issues and I am very careful. I check the digital signatures and upload each installer to VT.
 
F

ForgottenSeer 114834

The links in Softpedia are direct links to official websites. I never had any issues and I am very careful. I check the digital signatures and upload each installer to VT.
To empower forum readers to achieve the best possible outcomes...

Third-Party Sites Like Softpedia Can Be Compromised.

Here's how it can happen:

Malware Injection: Hackers can infiltrate the site and replace legitimate software downloads with malicious ones.

Supply Chain Attacks: The software developers themselves might be compromised, leading to tainted downloads even on reputable platforms.

Compromised Advertisements: Malicious ads can redirect users to harmful websites or download malware.

Data Breach: If the site's database is breached, user information could be stolen, potentially leading to targeted attacks.

How to Protect Yourself:

Verify Software Sources: Always download software directly from trusted developers or official websites.
 

Azure

Level 28
Verified
Top Poster
Content Creator
Oct 23, 2014
1,714
To empower forum readers to achieve the best possible outcomes...

Third-Party Sites Like Softpedia Can Be Compromised.

Here's how it can happen:

Malware Injection: Hackers can infiltrate the site and replace legitimate software downloads with malicious ones.

Supply Chain Attacks: The software developers themselves might be compromised, leading to tainted downloads even on reputable platforms.

Compromised Advertisements: Malicious ads can redirect users to harmful websites or download malware.

Data Breach: If the site's database is breached, user information could be stolen, potentially leading to targeted attacks.

How to Protect Yourself:

Verify Software Sources: Always download software directly from trusted developers or official websites.
What if the official website links to a 3rd party download site?
 
  • Like
Reactions: [correlate]

wat0114

Level 13
Verified
Top Poster
Well-known
Apr 5, 2021
619
A strict browser extension policy will block any unauthorized attempts to install additional extensions of any kind:

extension blocked by policy.png

In this case the browser itself has a policy enforced to restrict what it can do.
 
F

ForgottenSeer 114834

What if the official website links to a 3rd party download site?
If the official website redirects you to a third-party site download:

Verify the Third-Party Site: Check if the third-party site is well-known and reputable. Look for reviews or feedback from other users about the site.

Check for Official Endorsements: Sometimes, official websites partner with trusted third parties for distribution. Look for any endorsements or partnerships mentioned on the official site.

Look for Digital Signatures: When you download the software, check if the file is digitally signed by the publisher. This can often be verified through the file properties on your computer.

Use Antivirus Software: Ensure your antivirus software is up-to-date and scan the downloaded file before opening it.

Seek Alternatives: If you're uncomfortable with the third-party site, try to find an alternative official source or contact the software provider directly for guidance.
 

Studynxx

Level 3
Jan 20, 2023
209
I found a great way to install software without heading to each app's website. I created a Softpedia account and added the apps I am using to my Watchlist. Whenever an app receives an update, I get notified via email. I head to Softpedia which gives direct links to download the apps from their official sources.

An example of Softpedia email notifications
You should just use a Winget script to be honest.
 
  • Like
Reactions: Divine_Barakah

Trident

Level 34
Verified
Top Poster
Well-known
Feb 7, 2023
2,351
You should just use a Winget script to be honest.
It’s not about the source and way only, Malware not once or twice has made its way to all stores, including the rigorously-checking Apple App Store.

Users should just lose the habit of downloading everything they see. Working with a small set of trusted apps is essential for security.

For example, look at the malicious apps on Android Play Store, identified by BD.
Developer NameEmailWebsite
Qasim.LlcSteelrbasic@gmail.comhttps://personalitycharginshow[.]xyz
ALCANTARA.LabTipAprilb@gmail.comhttps://smartqrscanner1[.]xyz
Baig.CorpIssissppifinest2@gmail.comhttps://animatesstickermaster[.]xyz
Hamid.Appsjemarchag@gmail.comhttps://gps1ocationfinder[.]xyz
Emmanuel.LlcQuintonjxus@gmail.comhttps://mygps123123[.]xyz
Jamie.Labjjamiemunoz417@gmail.comhttps://artgirlswallpaperhd[.]xyz
Bennington.Llckkarlbennington@gmail.comhttps://catsimulator1[.]xyz
Josh.Lnchuhua.luc@gmail.comhttp://smartwifii123[.]xyz
Vern.AppsVernl3138@gmail.comhttps://imagewarpcamera[.]xyz
VILORIA.CorpJamelpmac@gmail.comhttps://smartqrcreator1[.]xyz
Abid.Studioita.mita594@gmail.comhttps://colorizeoldphoto[.]xyz
Adeel.Studioikvznj@gmail.comhttps://smartaps1ocation[.]xyz
Haq.CorpWycliffedennis07@gmail.comhttps://secrethoroscope1[.]xyz
Nadeem.AppsKnowMonty@gmail.comhttps://volumecontroll[.]xyz
Cedrick.CorpCedrickoayz@gmail.comhttps://gps1ocationmaps[.]xyz
RICHARD.LncFlossiezxe@gmail.comhttps://girlsartwallpaper[.]xyz
Sushil.Devtacie.bush@gmail.comhttps://mediavolumeslider[.]xyz
Haider.StudioEduardoaunx@gmail.comhttps://sleepsoundss[.]xyz
Kumar.AppsRandytzjp@gmail.comhttps://qrcreatorr12[.]xyz
Waseem.LlcMarquisDunlap35@gmail.comhttps://secretastrology[.]xyz/
Butt.Corpeterbrellocvx@gmail.comhttps://colorizephotos[.]xyz/
Vledern Studiodeernivle67@gmail.com-
I am not sure why anyone would need personality charging show, media volume slider or car simulator.

Browsers nowadays have become massive collection of tools, not sure what’s there to “extend”.
 
  • Like
Reactions: Divine_Barakah

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top