ChromeLoader malware threatens Windows and macOS, how to protect yourself?



During May, a rather high diffusion of malware ChromeLoaderwhich allows its operators to carry out transactions hijacking on the browser in order to promote unwanted software, open pages devoted to surveys and sweepstakes, as well as adult games and bogus dating sites. All this with the aim of earning money through affiliation. Among the various hijackers on the network, ChromeLoader stands out for its persistence on systems, for its spread and for the methods of infection that involve intensive use of PowerShell.

The wanted people of Red Canary have been tracking this malware since February and have identified the primary attack vector, which is an ISO archive file used by cybercriminals to infect victims’ systems. The ISO file was camouflaged as a cracked executable file, for games or commercial software pirateswhich was downloaded independently by users through compromised sites or containing lists of torrent files, complete with a promotional campaign on Twitter, where Android games subject to cracks and QR codes that directed users to sites were presented dangerous.

Malware often affects web browsers

Once the file was run on Windows, with the ISO mount as a virtual drive, the user found an executable inside it, passed off as crack or keygen, which is a program that generates bogus license codes. Once the file was run, ChromeLoader ran, decrypting a PowerShell command to recover a remote archive, loaded as a Google Chrome extension. At the end of the operation, there was no trace of the activity, only the extension that, in a discreet way, hijacked Chrome on the sites of interest of the operators. The same, however, was found on macOS, where the compromised files were of type DMG, with one bash script able to download and unpack the ChromeLoader extension to a temporary directory.

For get rid of the threatboth Google and Apple have prepared special guides, freely available:



As always, we remind you that downloading pirated materials is illegalbut also a lot dangerousas you expose yourself to serious risks, not least the possibility of suffering an attack ransomware.



Related News

‘Crypto Aims Not To Play Games With Million Dollar Pictures Of Monkeys’: Ethereum Founder Shot At Bored Ape Yacht Club

The non-fungible token has increased in interest and value over the past year, with Bored Ape Yacht Club One of the most popular and valuable collections.

10 places that Google Maps hides: military installations, famous houses, islands or crime scenes

Within the ecosystem of Google applications, one of the tools that many of us could not live without is Google Maps, since the great G maps app allows us to

Three tricks that will help you use your Android mobile with one hand

Over the years, mobile screens have not stopped growing. Compact mobiles are in extinction, since most users want a mobile with a large screen.

How to charge mobile phone without charger

It is usually an indispensable device throughout our day, so much so that if we find ourselves without our charger we can be cut off if we find ourselves

iPadOS 16 will bring floating windows in apps if external keyboards are connected

The new iPads are now available for purchase and the first units are beginning to reach the winners. The novelties introduced by Apple bring the iPad Air

Obfsproxy: know what it is and how it encrypts your connection

Therefore, Obfsproxy is a project created from Tor to improve privacy of the users. It is a way to avoid possible blocks that may exist for the use of a