Cyber Security

Beware Of Fake Google Chrome Update That Delivers Malware

An ongoing fake Google Chrome update effort targeting France has been noticed, which spreads WarmCookie malware via compromised websites. WarmCookie is a Windows malware that is used to obtain system access through phishing operations.

It is a two-stage backdoor intended to spread more payloads and examine target networks. It most commonly spreads through phishing efforts that impersonate job offers.

Warm cookies can be used as fingerprint machines, take screenshots, exfiltrate stolen data, read and write files, and interact with a command and control (C&C) server to get commands.

Overview Of The Fake Update Campaign

Gen Threat Labs claims that WarmCookie has also been updated.

Analyse Any Suspicious Links Using ANY.RUN’s New Safe Browsing Tool: Try for Free

The latest version supports the following commands:

  • Get CPU identification and memory size
  • Take screenshots
  • Enum programs via Uninstall reg key
  • cmd execution via cmd.exe /c and send back results via POST
  • Write the file to the victim
  • Read the file and send it back
  • Write DLL to %TEMP% and run it via rundll32.exe and send back the output
  • Same as 8, but starts it with “Start /update” arguments
  • Copies itself to %TEMP%
Fake Update Infected Webpage

WarmCookie malware is downloaded when a user clicks on the FakeUpdate-infected webpage. Once installed, it contacts C&C for further operations, takes a screenshot, executes the command, and steals data from the disk.

Distribution of the WarmCookie Malware

In June, Elastic Security Labs released a report on a phishing effort that uses lures related to jobs and recruitment to spread WarmCookie malware.

Since the end of April, attack chains have been noticed, and email messages from employment agencies such as Hays, Michael Page, and PageGroup have been used to persuade recipients to click on an embedded link to access information about a job opportunity.

Hence, by taking proactive actions to check the credibility of updates and adopting robust safety solutions, users may considerably decrease the chance of falling prey to such sophisticated attacks.

IoCs:

  • updatechrllom[.]com
  • javadevssdk[.]commozilaupgrade[.]com
  • edgeupgrade[.]comelrifeno[.]com
  • /temp/Install_x64[.]exe
  • 44faed020d5d8b29918a3f02d757b2cfada675
  • 74cf9e02748ea7f75ba5878907
  • 38[.]180[.]91[.]117

Free Webinar on How to Protect Small Businesses Against Advanced Cyberthreats -> Free Webinar

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

2 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

12 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

13 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

14 hours ago