Back to Hub

Chrome Exploited as Gateway for Resurgent High-Risk Malware, Researchers Warn

Imagen generada por IA para: Investigadores alertan: Chrome es usado como puerta de entrada para malware peligroso

A sophisticated malware campaign exploiting Google Chrome's market dominance has security professionals on high alert. The newly identified threat vector uses Chrome's trusted branding as camouflage while delivering multiple payload stages capable of complete system compromise.

Technical Analysis:
The malware employs a multi-stage delivery system beginning with compromised Chrome extensions that bypass the Web Store vetting process. Once installed, these extensions download secondary payloads that exploit either:

  • CVE-2023-7024 (Chrome's WebGL memory corruption vulnerability)
  • Zero-day flaws in Chrome's File System Access API

Behavioral Characteristics:

  1. Masquerades as Chrome update processes (chrome_update.exe)
  2. Implements process hollowing to inject malicious code into legitimate system processes
  3. Establishes persistent C2 connections using DNS-over-HTTPS (DoH) for stealth

Impact Assessment:
The malware's capabilities include:

  • Keylogging and form grabbing for credential theft
  • Browser session hijacking
  • Deployment of ransomware modules
  • Establishment of reverse shells for remote access

Mitigation Recommendations:

  1. Enterprise:
  • Implement extension allowlisting
  • Deploy behavioral analysis tools
  • Enforce strict DoH traffic monitoring
  1. Individual Users:
  • Verify all extension permissions
  • Enable Chrome's Enhanced Protection mode
  • Regularly audit running processes for suspicious chrome_update instances

The malware's infrastructure shows similarities to previous campaigns attributed to both Russian cybercrime groups and North Korean state-sponsored actors, suggesting possible collaboration or code sharing in the cybercriminal underground.

Original sources

NewsSearcher

This article was generated by our NewsSearcher AI system, analyzing information from multiple reliable sources.

Chrome als Einfallstor: Forscher warnen vor besonders gefährlicher Malware

CHIP Online Deutschland
View source

Chrome als Einfallstor: Forscher warnen vor besonders gefährlicher Malware

CHIP Online Deutschland
View source

⚠️ Sources used as reference. CSRaid is not responsible for external site content.

This article was written with AI assistance and reviewed by our editorial team.

Comentarios 0

¡Únete a la conversación!

Sé el primero en compartir tu opinión sobre este artículo.