This extension looks like it’s from Google, but it’s stealing your passwords in Chrome


The google chrome extensions They are one of the techniques most used by hackers to infect users’ computers. Given its popularity, tricking victims into installing a Google Chrome extension is a relatively simple phishing technique, and if done right, it can even go undetected for years, as has happened with this malicious extension that has been stealing cryptocurrency and passwords to thousands of users.

This extension masquerades as an apparently official Google Sheets (Google spreadsheets) extension. However, it is an add-on installed by the malware for Windows ViperSoftX, a RAT (Remote Access Trojan) that seeks to take control of users’ computers.

How ViperSoftX malware works

This malware (along with its VenomSoftX variant) has been active since 2020, and has been seen operating in numerous countries, both in the United States and in South America and Europe. In 2022, this Trojan has returned to its old ways in a much more aggressive way to recover the number of controlled computers that it had years ago.

The distribution way of this malware is mainly through illegal downloads. As the security firm Avast warns, it has been found in many pirate games downloaded from torrentas well as many activators and programs previously activated with illegal techniques.

The first versions of this Trojan hid on the computer waiting to receive orders from a remote control server to start acting. However, although the new versions and variants are broadly similar, hackers have sought to take advantage of Google Chrome in order to have even more control over computers and, incidentally, make it easier to capture cryptocurrencies, passwords and other sensitive information. of the victims.

Google Sheets 2.1: the nightmare extension

At the beginning of the year, the malware installed an extension called “Update Manager” in the browser. However, the latest versions of this Trojan have changed its name to Google Sheets 2.1. In this way, it perfectly masquerades as the Google extension and can remain installed without arousing suspicion.

Malicious Extension Google Sheets

The objective of this extension is simple: to remain installed on the PC for as long as possible in order to steal all the cryptocurrency wallets of the victims. The wallets it targets are Blockchain.com, Binance, Coinbase, Gate.io, and Kucoin, though it also checks the clipboard for any copied blockchain addresses. In addition to actively searching for cryptocurrencies, this malware also targets the password theft of the victims.

When it collects all the information, it sends a file with the captured cryptocurrency addresses and passwords to the hackers’ server.

How to find and remove it

Google Sheets in Chrome is installed as an app (ie inside chrome://apps) and not as an extension. Therefore, the fastest way to see if we have it installed or not is to write chrome://extensions in the address bar, and look for the Google Sheets extension. If you do, be careful. we are infected by this malwareand we will have to remove the extension, and scan the computer with a good antivirus to completely remove it from the PC.

If this extension does not appear on the computer (and neither is it called Update Manager), then we are in luck, and our PC is safe.


Related News

Masz dużo! (2023) – recenzja filmu [Canal+]. Typowa komedia o polskiej mentalności

The movie "You're in luck!" tells the story of the Bednarski family, who learn that their deceased grandfather Józef (Mikołaj Grabowski) was buried with a

Sprawdź, kiedy zmienia się Twój publiczny adres IP i jak to zmienić

Być może zastanawiasz się, czy Twój publiczny adres IP jest statyczny czy dynamiczny. Dzięki temu dowiesz się, czy się zmieni, czy zawsze pozostanie taki sam. Musisz to wiedzieć

Opera dodaje ChatGPT do swojego paska bocznego [Wideo]

ChatGPT debiutuje pod koniec 2022 r., a kiedy rozpocznie się 2023 r., sztuczna inteligencja nadal będzie miała duże znaczenie dla dużych technologii. A teraz ponownie uruchamia wojny przeglądarek, podobnie jak Opera

Dlaczego reklama Apple Macintosh Super Bowl z 1984 roku jest teraz bardziej aktualna niż kiedykolwiek

W styczniu 1984 roku Apple był bliski debiutu swojego następcy zarówno Apple II, jak i Lisy — który miał nosić nazwę Macintosh. Ale to była reklama w trakcie

Błąd 0x80072745, Nawiązane połączenie zostało przerwane przez oprogramowanie na komputerze hosta

In this article, we will look at ways to fix it Error 0x80072745, An established connection was aborted by software in your host machine, This is a server