Trojan Poses as Fake Google Chrome Extension
Apr 19th, 2010 | Category: BitDefenderToday BitDefender warns, as more and more people are using Google Chrome and its functionalities to browse the net and to organize information, cybercriminals are setting their minds on exploiting this environment to spread malware and steal users information.
The story is simple: Google Chrome users receive an unsolicited e-mail which announces that a new extension of their favorite browser has been developed to facilitate their access to documents from e-mails.
An apparently unsuspicious link is provided, and the recipients are advised to follow it in order to download the new extension. Once they click the link, they are redirected to a look-alike of the Google Chrome Extensions page, which, instead of the promised extension, provides them with a fake application that infects their systems with malware.
Although the sham application has the same description as that of an original Google Chrome Extension, the first sign the more inquisitive users will get about it not being what they were looking for should be the fact that instead of the expected .crx extension, it features a flamboyant .exe tail.
Identified by BitDefender as Trojan.Agent.20577 the application modifies the Windows HOSTS file in an attempt to block access to Google and Yahoo webpages. Every time users want to access them and write google.[xxx] or [xx].search.yahoo.com in the web browser, they will be redirected to another IP: 89.149.xxx.xxx . This allows the malware creators to intercept the victims calls to reach the respective sites. In this way, the credulous users will be redirected to the cybercriminals own malware-laden versions of those sites.
About BitDefender®
BitDefender is the creator of one of the industry’s fastest and most effective lines of internationally certified security software. Since its inception in 2001, BitDefender has continued to raise the bar and set new standards in proactive threat prevention. Every day, BitDefender protects tens of millions of home and corporate users across the globe – giving them the peace of mind of knowing that their digital experiences will be secure. BitDefender solutions are distributed by a global network of value-added distribution and reseller partners in more than 100 countries worldwide. More information about BitDefender and its products are available at the companys security solutions press room. Additionally, BitDefenders www.malwarecity.com provides background and the latest updates on security threats helping users stay informed in the everyday battle against malware.
Related Posts
No related posts.