216.73.216.6

New Widespread Extension Trojan Malware Campaign

· Published 07/08/2024 08:33 · Modified 07/08/2024 09:06

Export JSON

Essential information

Published
07/08/2024 08:33
Modified
07/08/2024 09:06
Tags
2024-08-07 adware bankshot browser extensions hijacking polymorphic trojan
Related entities
11 techniques (mitre), 3 malware

Description

This report discusses a widespread malware campaign that forcefully installs malicious on endpoints. The malware, originating from imitations of download websites, delivers various malicious payloads, including , data stealing scripts, and commands to execute. It hijacks searches, redirects traffic, and has affected over 300,000 users across Google Chrome and Microsoft Edge. The malicious actors employ obfuscation techniques, leverage PowerShell scripts, and communicate with command-and-control servers to receive instructions and download additional malicious components.

External references