Back to Hub

Chrome Exploited as Gateway for Resurgent High-Risk Malware, Researchers Warn

Imagen generada por IA para: Investigadores alertan: Chrome es usado como puerta de entrada para malware peligroso

A sophisticated malware campaign exploiting Google Chrome's market dominance has security professionals on high alert. The newly identified threat vector uses Chrome's trusted branding as camouflage while delivering multiple payload stages capable of complete system compromise.

Technical Analysis:
The malware employs a multi-stage delivery system beginning with compromised Chrome extensions that bypass the Web Store vetting process. Once installed, these extensions download secondary payloads that exploit either:

  • CVE-2023-7024 (Chrome's WebGL memory corruption vulnerability)
  • Zero-day flaws in Chrome's File System Access API

Behavioral Characteristics:

  1. Masquerades as Chrome update processes (chrome_update.exe)
  2. Implements process hollowing to inject malicious code into legitimate system processes
  3. Establishes persistent C2 connections using DNS-over-HTTPS (DoH) for stealth

Impact Assessment:
The malware's capabilities include:

  • Keylogging and form grabbing for credential theft
  • Browser session hijacking
  • Deployment of ransomware modules
  • Establishment of reverse shells for remote access

Mitigation Recommendations:

  1. Enterprise:
  • Implement extension allowlisting
  • Deploy behavioral analysis tools
  • Enforce strict DoH traffic monitoring
  1. Individual Users:
  • Verify all extension permissions
  • Enable Chrome's Enhanced Protection mode
  • Regularly audit running processes for suspicious chrome_update instances

The malware's infrastructure shows similarities to previous campaigns attributed to both Russian cybercrime groups and North Korean state-sponsored actors, suggesting possible collaboration or code sharing in the cybercriminal underground.

Original source: View Original Sources
NewsSearcher AI-powered news aggregation

Comentarios 0

¡Únete a la conversación!

Sé el primero en compartir tu opinión sobre este artículo.