Go to listing page

ChromeLoader Operators Hide Malware in VHD Files for Game Cracks

ChromeLoader Operators Hide Malware in VHD Files for Game Cracks
The ChromeLoader browser hijacking malware has recently changed its tactics against victims. Previously, the malware leveraged websites promoting fake giveaways, unwanted software, surveys, adult games, and dating sites to infect victims. Lately, has been found using malicious VHD files for popular games to trick users into downloading the malware.

More in detail

ASEC security researchers have discovered a steady rise in the use of disk image files, such as ISO and VHD, to distribute ChromeLoader browser hijacking malware.
  • In the ongoing campaign, malicious VHD files are designed to appear like either hacks or cracks for Nintendo and Steam, Call of Duty, Need for Speed, Portal 2, Minecraft, Legend of Zelda, Pokemon, Mario Kart, Animal Crossing, and Dark Souls 3.
  • When a VHD file is downloaded, the user is redirected to a network of malvertising sites distributing the ChromeLoader extension.
  • ChromeLoader hijacks browser searches to show advertisements and later modifies the browser setting and collects credentials and browser data.


Evolution of ChromeLoader 

  • According to Red Canary, the malware caused widespread damage in May 2022. Since the beginning of the month, the malware operators used it to target both Windows and macOS systems. 
  • In July 2022, Palo Alto Unit 42 Network researchers reported new variants of ChromeLoader, highlighting its evolving feature set in a short span of time.
  • The infections chain works by enticing unsuspecting users into downloading movie torrents of cracked video games through malvertising campaigns on pay-per-install sites and social media. 
  • In September 2022, VMware and Microsoft warned of a widespread ChromeLoader campaign that dropped node-WebKit malware and even ransomware in some cases. 

Conclusion

ChromeLoader has been rapidly evolving, boasting a wide range of capabilities. ASEC has provided a set of IOCs that can help organizations to detect the malware coming via VHD files. Additionally, users must avoid downloading games from unofficial sources and keep away from cracks for popular products.
Cyware Publisher

Publisher

Cyware