ChromeLoader malware threatens Windows and macOS, how to protect yourself?



During May, a rather high diffusion of malware ChromeLoaderwhich allows its operators to carry out transactions hijacking on the browser in order to promote unwanted software, open pages devoted to surveys and sweepstakes, as well as adult games and bogus dating sites. All this with the aim of earning money through affiliation. Among the various hijackers on the network, ChromeLoader stands out for its persistence on systems, for its spread and for the methods of infection that involve intensive use of PowerShell.

The wanted people of Red Canary have been tracking this malware since February and have identified the primary attack vector, which is an ISO archive file used by cybercriminals to infect victims’ systems. The ISO file was camouflaged as a cracked executable file, for games or commercial software pirateswhich was downloaded independently by users through compromised sites or containing lists of torrent files, complete with a promotional campaign on Twitter, where Android games subject to cracks and QR codes that directed users to sites were presented dangerous.

Malware often affects web browsers

Once the file was run on Windows, with the ISO mount as a virtual drive, the user found an executable inside it, passed off as crack or keygen, which is a program that generates bogus license codes. Once the file was run, ChromeLoader ran, decrypting a PowerShell command to recover a remote archive, loaded as a Google Chrome extension. At the end of the operation, there was no trace of the activity, only the extension that, in a discreet way, hijacked Chrome on the sites of interest of the operators. The same, however, was found on macOS, where the compromised files were of type DMG, with one bash script able to download and unpack the ChromeLoader extension to a temporary directory.

For get rid of the threatboth Google and Apple have prepared special guides, freely available:



As always, we remind you that downloading pirated materials is illegalbut also a lot dangerousas you expose yourself to serious risks, not least the possibility of suffering an attack ransomware.



Related News

The Galaxy Z Fold4 and Flip4 leak in press photos

Just yesterday, an image published by Evan Blass I suggested that Samsung could hold your Galaxy Unpacked event to introduce the Galaxy ZFold 4 and to Galaxy

Intel Arc A770, Rivaling RTX 3060 Ti

Intel, which is selling Arc A380 graphics cards, is preparing to launch high-end graphics cards such as Arc A750 and Arc A770. Similar to NVIDIA's Founders

So you can make your Xiaomi mobile concentrate all the WiFi signal in a single app

The speed of the internet is measured in megabits per second (Mbps), it means that a megabit has 1024 kilobits (Kbps), therefore 1 Mbps is a thousand times

Android: why you should not charge your cell phone to 100%

Are you one of the people who leaves carrying the cell phone all night? Well, we tell you that this can be harmful not for you, but for your smartphone.

WhatsApp: how to save data when you make a call or video call

Do you run out of megabytes on your cell phone too quickly? WhatsApp is possibly responsible for doing so. The messaging application has an infinite number of

The guide to remove the internal dust that is in the speakers of your Xiaomi phone

Most users normally clean the outside of their phone Android with a damp cloth or dry cloth, however, dirt also enters through the speaker holes and could