Jump to content
  • Malicious browser extensions leveraged in widespread malware compromise

    aum

    • 359 views
    • 1 minutes
     Share


    • 359 views
    • 1 minutes

    More than 300,000 Google Chrome and Microsoft Edge users have been impacted by a massive ongoing malware campaign involving malicious browser extensions that facilitate data exfiltration and command execution while bypassing antivirus tools, reports BleepingComputer.

     

    Malvertising exploiting Google search results has been leveraged to lure victims into downloading fraudulent software installers, including YouTube downloader, Roblox FPS Unlocker, and VLC video player, which run a PowerShell script enabling payload retrieval and execution, as well as forces installation of extensions, all of which have since been removed from the Chrome and Edge stores, according to a report from ReasonLabs. Such extensions have been used to enable search query takeovers and redirections to revenue-generating pages, as well as allow login credential theft, online activity tracking, and command execution. Aside from altering browser shortcut links to load the extensions, such payloads also hinder further security updates, said researchers, who noted that infections could be remediated only through a multi-step process involving the removal of a scheduled task, malicious registry entries, and malware files.

     

    Source


    User Feedback

    Recommended Comments

    There are no comments to display.



    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...