Jump to content

Malware Can Bypass Chrome Extension Security Feature Easily

Bloodyvalley

1024px-Chrome_Logo.svg.png

 

 

Researchers have uncovered a new social engineering trick that leads users to a malicious extension from Google Chrome impersonating to deliver Adobe’s Flash Player in order to lure victims in a click fraud campaign.
 
Security experts at TrendMicro believe that the malware is triggered by opening Facebook or Twitter via shortened links provided in any social networking websites. Once clicked, the links may lead victims to a site that automatically downloads the malicious browser extension.
 
MALWARE INVOLVES DOWNLOADING MULTIPLE MALICIOUS FILES
The process is quite complicated as the malware drops a downloader file which downloads multiple malicious files on the victim’s computer. Moreover, the malicious program also has ability to bypass Google's recent security protection added to Chrome against installation of browser extensions that are not in Chrome Web Store.
 
 

Researchers came across a baiting tweet that advertises “Facebook Secrets”, claiming to show videos that are not publicly available, along with a shortened link that is to be clicked in order to get it. Curious users easily fall victim to such campaign and click the given links to download those videos.
 
What the user totally unaware of is that the file which he downloaded is a malware dropper with the name “download-video.exe”, detected as TROJ_DLOADE.DND, according to fraud analyst Sylvia Lascano of the security firm Trend Micro.
 
This malicious file then is used to drop additional malware into the victims’ computer, one such is a Chrome browser extension which masquerades as Flash Player, which could be used for more offensive threats designed to steal victims’ credentials for various online services.
 
MALWARE BYPASSES GOOGLE’S SECURITY POLICY
In order to evade detection, the malware circumvents Google's security policy – which only allows extension installations hosted in the Chrome Web Store – by creating a folder in the browser's directory where it drops “browser extension components.”
FB-secret-3.jpg
The browser extension components that needs to be loaded are added to Chrome’s extension folder are as follows:
 
  • manifest.json – contains browser extension description like name, script to load, version, etc.
  • crx-to-exe-convert.txt – contains the script to be loaded, which can be updated anytime by connecting to a specific URL.
After all the data is parsed by the browser in the dropped component manifest.json, the extension is ready to work.
 
OPEN FACEBOOK OR TWITTER – BE A VICTIM OF CLICK FRAUD
Once installed, if a user visits Facebook or Twitter, the extension quietly opens a specific site in the background that is written in Turkish, which researchers believe is part of a click fraud or redirection scheme.

The site is written in Turkish and phrases such as ‘bitter words,’ ‘heavy lyrics,’ ‘meaningful lyrics,’ ‘love messages,’ and ‘love lyrics’ appear on the page. This routine could be a part of a click fraud or redirection scheme
,” fraud analyst Sylvia Lascano of the security firm Trend Micro said in a
.

SHORTENED LINK HELPED THREAT ACTORS
By the time researchers discovered the campaign, the tweets promoting the sophisticated malware dropper had been retweeted more than 6,000 times.
 
Here cyber criminals took help of shortened link in order to victimize a large number of victims because of the fact that the shortened link don’t have visibility of where it directs, and contributes to spreading the campaign.
 
So, in order to protect your computers against this sort of threats, avoid accessing links from any unknown and suspicious sources.
 

 

Source

 

One image: firefox-logo.png

Link to comment
Share on other sites

Link to post
Share on other sites

In before FF fanboys?

 

I do use it myself, but it's hardly perfect :P

Case: Meatbag, humanoid - APU: Human Brain version 1.53 (stock clock) - Storage: 100TB SND (Squishy Neuron Drive) - PSU: a combined 500W of Mitochondrial cells - Optical Drives: 2 Oculi, with corrective lenses.

Link to comment
Share on other sites

Link to post
Share on other sites

Oh look, trend micro, the service I use. WOOT. How/why has chrome caught on? I've heard nothing but bad things about it so far.

 

 

I use neither Facebook nor Twitter. Good!

Same, if your using those you deserve a virus because you are one.

Ketchup is better than mustard.

GUI is better than Command Line Interface.

Dubs are better than subs

Link to comment
Share on other sites

Link to post
Share on other sites

Same, if your using those you deserve a virus because you are one.

 

TIL that using popular social networking sites to stay in touch with family/old friends means you're a virus. Good to know.

Link to comment
Share on other sites

Link to post
Share on other sites

i stopped using chrome when it stopped allowing me to run Utorrent .... (called it a malicious file)

If your grave doesn't say "rest in peace" on it You are automatically drafted into the skeleton war.

Link to comment
Share on other sites

Link to post
Share on other sites

TIL that using popular social networking sites to stay in touch with family/old friends means you're a virus. Good to know.

Telephone-Invention-Story.jpg

"Social networking" is degrading society and making people stupid, sorry. Try just calling someone and talking to them instead.

Ketchup is better than mustard.

GUI is better than Command Line Interface.

Dubs are better than subs

Link to comment
Share on other sites

Link to post
Share on other sites

-snips-

"Social networking" is degrading society and making people stupid, sorry. Try just calling someone and talking to them instead.

Not many people know what a house phone is anymore.. :(

.

Link to comment
Share on other sites

Link to post
Share on other sites

Not many people know what a house phone is anymore.. :(

Same here. Growing up all anyone my age was willing (or capable) of talking about was who did/said/posted what to whom on facebook/myspace etc. Congratulations social media, you have killed not only intelligence in general, but the art of good conversation about things that actually matter.

 

Shut down facebook, before it's too late.

Ketchup is better than mustard.

GUI is better than Command Line Interface.

Dubs are better than subs

Link to comment
Share on other sites

Link to post
Share on other sites

I have been using google chrome on my mac for a while now. I may switch to safari, but is there a way to import all your bookmarks and what not?

 eGPU Setup: Macbook Pro 13" 16GB DDR3 RAM, 512GB SSD, i5 3210M, GTX 980 eGPU

New PC: i7-4790k, Corsair H100iGTX, ASrock Fatal1ty Z97 Killer, 24GB Ram, 850 EVO 256GB SSD, 1TB HDD, GTX 1080 Fractal Design R4, EVGA Supernova G2 650W

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

"Social networking" is degrading society and making people stupid, sorry. Try just calling someone and talking to them instead.

 

I wouldn't say it's degrading society, I don't think people would be any less stupid if they had to call/text a friend instead of talking to them on Facebook.

Link to comment
Share on other sites

Link to post
Share on other sites

Get malwarebytes anti-exploit it stops side downloads like this shit.

cpu: intel i5 4670k @ 4.5ghz Ram: G skill ares 2x4gb 2166mhz cl10 Gpu: GTX 680 liquid cooled cpu cooler: Raijintek ereboss Mobo: gigabyte z87x ud5h psu: cm gx650 bronze Case: Zalman Z9 plus


Listen if you care.

Cpu: intel i7 4770k @ 4.2ghz Ram: G skill  ripjaws 2x4gb Gpu: nvidia gtx 970 cpu cooler: akasa venom voodoo Mobo: G1.Sniper Z6 Psu: XFX proseries 650w Case: Zalman H1

Link to comment
Share on other sites

Link to post
Share on other sites

I wouldn't say it's degrading society, I don't think people would be any less stupid if they had to call/text a friend instead of talking to them on Facebook.

You'd be surprised. All any of the younger generations seem to care about is facebook bullshit, try talking politics and you might as well be speaking martian.

Ketchup is better than mustard.

GUI is better than Command Line Interface.

Dubs are better than subs

Link to comment
Share on other sites

Link to post
Share on other sites

You'd be surprised. All any of the younger generations seem to care about is facebook bullshit, try talking politics and you might as well be speaking martian.

 

Try to talking to an average teenager about politics 20-30 years ago and you'd probably get the same result.

Link to comment
Share on other sites

Link to post
Share on other sites

Try to talking to an average teenager about politics 20-30 years ago and you'd probably get the same result.

uuuuummmm..... ever hear of the 60/70's? Teenagers used to be a lot smarter on average than they are now. At least more involved in the world around them.

Ketchup is better than mustard.

GUI is better than Command Line Interface.

Dubs are better than subs

Link to comment
Share on other sites

Link to post
Share on other sites

uuuuummmm..... ever hear of the 60/70's? Teenagers used to be a lot smarter on average than they are now. At least more involved in the world around them.

 

Care to provide a source for your claims? or are you just talking out of your ass?

Link to comment
Share on other sites

Link to post
Share on other sites

Oh look, trend micro, the service I use. WOOT. How/why has chrome caught on? I've heard nothing but bad things about it so far.

 

 

Same, if your using those you deserve a virus because you are one.

facebook does deserves all the shit it can have, there's no doubt about that

 

twitter in the other hand is different, it can't be compared to facebook expect that is social media but it doesn't work the same way, and it mainly doesn't pull the background bullshit facebook does, i use it mostly as a news feed and follow a few youtubers (linus and group included) also if your worried about privacy, twitter gives you full control of the content you make and when you are exposed

 

ohh and because people spend their time trash talking on facebook or whatever, doesn't mean they deserve a virus, there's usually something worst in the long term

this is one of the greatest thing that has happened to me recently, and it happened on this forum, those involved have my eternal gratitude http://linustechtips.com/main/topic/198850-update-alex-got-his-moto-g2-lets-get-a-moto-g-for-alexgoeshigh-unofficial/ :')

i use to have the second best link in the world here, but it died ;_; its a 404 now but it will always be here

 

Link to comment
Share on other sites

Link to post
Share on other sites

Sorry but I'm a FF fanboy so you're late

Well damn, now I feel bad about that :c

Case: Meatbag, humanoid - APU: Human Brain version 1.53 (stock clock) - Storage: 100TB SND (Squishy Neuron Drive) - PSU: a combined 500W of Mitochondrial cells - Optical Drives: 2 Oculi, with corrective lenses.

Link to comment
Share on other sites

Link to post
Share on other sites

uuuuummmm..... ever hear of the 60/70's? Teenagers used to be a lot smarter on average than they are now. At least more involved in the world around them.

Care to give a source to refute my claims? I simply feel that kids used to be smarter or at least more involved since they paid attention to something other than facebook/myspace/twitter. I grew up with a bunch of morons, it started with my generation (graduated 2007), I think my sisters generation (I think she graduated high school in 97-99) was the last intellectual generation, I just don't see much intelligence day to day going on in the world. *shrugs*

Ketchup is better than mustard.

GUI is better than Command Line Interface.

Dubs are better than subs

Link to comment
Share on other sites

Link to post
Share on other sites

Researchers have uncovered a new social engineering trick that leads users to a malicious extension from Google Chrome...


New? I encountered this a year or 2 ago.

| Intel i7-3770@4.2Ghz | Asus Z77-V | Zotac 980 Ti Amp! Omega | DDR3 1800mhz 4GB x4 | 300GB Intel DC S3500 SSD | 512GB Plextor M5 Pro | 2x 1TB WD Blue HDD |
 | Enermax NAXN82+ 650W 80Plus Bronze | Fiio E07K | Grado SR80i | Cooler Master XB HAF EVO | Logitech G27 | Logitech G600 | CM Storm Quickfire TK | DualShock 4 |

Link to comment
Share on other sites

Link to post
Share on other sites

If people think that downloading Adobe Flash Player for Google Chrome is a good idea then maybe they can't be helped no matter what.

Link to comment
Share on other sites

Link to post
Share on other sites

we need a new web browser. maybe like a community-assisted one. get everyone involved so it can be perfect kind of thing.

"If a Lobster is a fish because it moves by jumping, then a kangaroo is a bird" - Admiral Paulo de Castro Moreira da Silva

"There is nothing more difficult than fixing something that isn't all the way broken yet." - Author Unknown

Spoiler

Intel Core i7-3960X @ 4.6 GHz - Asus P9X79WS/IPMI - 12GB DDR3-1600 quad-channel - EVGA GTX 1080ti SC - Fractal Design Define R5 - 500GB Crucial MX200 - NH-D15 - Logitech G710+ - Mionix Naos 7000 - Sennheiser PC350 w/Topping VX-1

Link to comment
Share on other sites

Link to post
Share on other sites

#WFMR

#WFFTW

Don't think it's new that malware can pass Chromes security, knew this awhile ago...

 

Spoiler

Senor Shiny: Main- CPU Intel i7 6700k 4.7GHz @1.42v | RAM G.Skill TridentZ CL16 3200 | GPU Asus Strix GTX 1070 (2100/2152) | Motherboard ASRock Z170 OC Formula | HDD Seagate 1TB x2 | SSD 850 EVO 120GB | CASE NZXT S340 (Black) | PSU Supernova G2 750W  | Cooling NZXT Kraken X62 w/Vardars
Secondary (Plex): CPU Intel Xeon E3-1230 v3 @1.099v | RAM Samsun Wonder 16GB CL9 1600 (sadly no oc) | GPU Asus GTX 680 4GB DCII | Motherboard ASRock H97M-Pro4 | HDDs Seagate 1TB, WD Blue 1TB, WD Blue 3TB | Case Corsair Air 240 (Black) | PSU EVGA 600B | Cooling GeminII S524

Spoiler

(Deceased) DangerousNotDell- CPU AMD AMD FX 8120 @4.8GHz 1.42v | GPU Asus GTX 680 4GB DCII | RAM Samsung Wonder 8GB (CL9 2133MHz 1.6v) | Motherboard Asus Crosshair V Formula-Z | Cooling EVO 212 | Case Rosewill Redbone | PSU EVGA 600B | HDD Seagate 1TB

DangerousNotDell New Parts For Main Rig Build Log, Señor Shiny  I am a beautiful person. The comments for your help. I have to be a good book. I have to be a good book. I have to be a good book.

 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×