Scammers Use Download Bombs to Freeze Chrome Browsers on Shady Sites

Status
Not open for further replies.

Faybert

Level 24
Thread author
Verified
Top Poster
Well-known
Jan 8, 2017
1,318
The operators of some tech support scam websites have found a new trick to block visitors on their shady sites and scare non-technical users into paying for unneeded software or servicing fees.

The trick relies on using JavaScript code loaded on these malicious pages to initiate thousands of file download operations that quickly take up the user's memory resources, freezing Chrome on the scammer's site.

The trick is meant to drive panicked users into calling one of the tech support phone numbers shown on the screen. A GIF of one of these malicious sites freezing a Chrome browser running the latest version (64.0.3282.140) is embedded below.

Chrome_TSS.gif


According to Jérôme Segura —Malwarebytes leading expert in tech support scam operations, malvertising, and exploit kits— this new trick utilizes the JavaScript Blob method and the window.navigator.msSaveOrOpenBlob function to achieve the "download bomb" that freezes Chrome.

The expert says the only way to escape the tech support website is to close Chrome via Windows Task Manager.

When the user restarts Chrome, if Chrome is configured to reload the previous session, Segura advises users to quickly close the shady site while the page is loading and before the malicious code has a chance to execute.

"Download bomb" trick spotted after Google fixed previous trick
Segura says he spotted tech support scammers abusing this new trick after Google engineers patched Chrome against a previous technique that utilized the history.pushState API to similarly freeze Chrome browsers on shady sites.

This "download bomb" trick only works in Chrome, Segura said. Users landing on the same shady URLs but using other browsers are served different pages.

Also on the front of shady sites pushing malicious content, users should also be aware of sites pushing fake Adobe Flash update packages laced with CPU miners, but also of similar shady sites pretending to provide Mozilla Firefox updates.

GIF image credits: Malwarebytes

Article Source: Scammers Use Download Bombs to Freeze Chrome Browsers on Shady Sites
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top