Chrome extension Trojan tricks victims in an endless malware loop
People in several Central and South American countries who wanted to watch a video online are affected by a Trojan that redirects the viewers to a new URL that contains malicious content.
These events were discovered by ESET research team when there was a spike in the JS/ChromeX.Submelius threats activity. This redirect happens when the victim presses to play a video. When it is clicked a new window appears demanding the victim to download a Chrome extension and it will not close until the victim relents and downloads the extension.
That first downloads opens a window for the hacker to take up permission to read or change all of the user’ s data on sites which was visited by the victim to inject malware into each site.
“ Then, while the user is browsing the internet, they will suddenly see new windows opening up with information about their system, taking them to other websites containing downloads of malicious code, advertising, or other kinds of content. This becomes an endless loop, which ultimately will benefit whoever is behind the fraudulent extension,” ESET wrote.
The cure for this is easy, finding the rogue extension and deleting it the Chrome extension are will help the victims to get out of this endless loop they are trapped in.
Comments ( 1 )