Tech

beware of these fake updates, they are full of malware

Cybersecurity researcher Rintaro Koike revealed the existence of a large phishing campaign that aims to distribute malware. Hackers display fake error messages that trick people into installing a Chrome update from fake websites.

hacker-screens-pc
Credit: 123rf

As of November 2022, Me Koike discovers a phishing campaign which is spreading through a fake Chrome for Windows error message. The hackers have indeed inserted a malicious program into the code of a legitimate, but compromised site. A message is displayed on arrival on the home page and suggests that it is a browser alert. That’s all it takes to give some visitors confidence, who then click on the proposed update link.

It took cybercriminals more than three months to set up their scam. The researcher indeed discovered the preparation of this campaign in November 2022, but according to him, it would not have started until February 2023. The fruit of their work is effective, since their operating mode allows not to be spotted by the antivirus of their victims.

Hackers target all Internet users with malware available in 100 languages

This type of attack should soon be perpetrated all over the world. The malware is available in 100 languages, and with its three billion daily users, Chrome is a huge pool of potential victims. If a user visits a compromised site, and they meet the requirements, they see a message that there was a problem with the automatic update of Chrome.

To read – Cybersecurity: France is the 5th country most targeted by ransomware attacks

Don’t worry though, it’s just recommended to install the update a bit later, or wait for the next update. This reassuring message prompts some visitors to download the linked zip file. This file, once executed, “excludes itself from Windows Defender settings, suspends Windows update services”, then installs mining software for Monero, a virtual currency very popular with hackers. All this, without the target of the attack even realizing it. The expert recommendation is never to download any program from an unverified source.

Source : NTT Security Japan

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *