home.social

#chromeloader — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #chromeloader, aggregated by home.social.

  1. Cyber Security Updates
    Malware Loaders Responsible for 80% of Security Incidents
    Dealing with malware loaders poses intricate challenges for SOC teams.

    A recent exploration by ReliaQuest has unveiled a multitude of disruptive loader instances. Notably, the trio comprised of “QakBot” (also recognized as QBot, QuackBot, Pinkslipbot), “SocGholish,” and “Raspberry Robin” emerged as the predominant culprits.

    #QakBot #Gootloader #Guloader #Ursnif #Chromeloader #ACCESSYSTEM

  2. Sophos MDR has observed quite the uptick in #chromeloader infections. We found one instance where the infection stemmed from a fake Youtube Video Downloader site.

    🔎 Google search:download youtube video
    ➡️ User lands on hxxps://10downloader[.]com/en/51
    ➡️ User attempts to download a specific video
    ➡️ Redirection to hxxps://heinndoorh[.]com
    ➡️ Redirection to hxxps://llyighaboveth[.]com
    ➡️ Redirection to hxxps://adtwobrightsa.info/12557074
    ⬇️ Downloads the sample Your File Is Ready To Download.exe

    This often leads to the creation of a schtask such as \chrome display, \chrome disp, \chrome profile, and many more.

    Encoded powershell is invoked to create a registry key under HKCU:\Software\ with various paths such as:

    • AudioConverterStudio
    • FoxitSoftware
    • KCSoftwares
    • DTSoft
    • BinaryFortressSoftware

    #threatintel

  3. 📣 #ChromeLoader, which was formerly discovered lurking within fake #VPN and antivirus, has now expanded its reach to encompass well-known games and utility software.

    Read: hackread.com/roblox-nintendo-c

    #Security #Malware #Gaming #Roblox #Nintendo #cybersecurity

  4. Day 1️⃣​0️⃣​ of #100DaysOfYara: MacOS Browser Hijacker Scripts🍎​
    🔗​ github.com/colincowie/100DaysO

    Background on these MacOS malware scripts used by #ChromeLoader aka #ChoziosiLoader:
    📖​ redcanary.com/blog/chromeloade
    📖​ blogs.vmware.com/security/2022
    📖​ th3protocol.com/2022/Choziosi-

    Todays rule did a nice job of detecting the historical ChromeLoader scripts. A more generic yara rule for identifying .command script abuse would potentially be pretty interesting!

  5. Eine Chrome-Erweiterung kann allen Browserverkehr über unerwünschte Server leiten und so Daten abschöpfen. ChromeLoader geht dabei trickreich vor.
    Schädliche Browser-Erweiterung: ChromeLoader kommt als ISO getarnt
  6. Tech Wrap-Up Week 21 2022. Teen online #privacy & #safety, #blockchain & #DeFi flaws, #ChromeLoader #malware surge, #Chrome sucks at blocking #phishing sites, #cybersecurity & #coding, #WordPress 6.0 released, glitchy #Mac apps, new features expected at #WWDC22, Chrome 102 released, and protecting your #privacy in #Windows, all in this week's wrap-up. techhelpkb.com/tech-wrap-up-we