Cybercriminals are tampering with legitimate websites to spread cryptominer malware disguised as a Google Chrome update patch, Rintaro Koike, a SOC analyst at Japanese cybersecurity firm NTT Security Holdings, revealed on Tuesday.
This campaign has been active since February 2023, although it was first observed in November 2022. The attack targets Windows users and is designed to escape detection by tinkering with victims’ Windows Defender, Windows Update services, and antivirus software.
The ultimate goal of the attack is to deliver Monero cryptominer malware, which works in the background, adding load to the target’s CPU.
So far, the “widespread” attack has targeted Japanese, Spanish, and Korean sites. However, the fake error screen messages are multilingual, and the campaign may spread in the future, Koike warned.
Fake Chrome Error and Cryptominer Disguised as Patch
To infect victims, cybercriminals inject malicious JavaScript code into websites which redirects visitors to an error screen. The error message reads: “An error occurred in Chrome automatic update. Please install the update package manually later, or wait for the next automatic update.”
Several websites, including blogs, news sites, online stores, and adult sites, have been compromised in this campaign.
Users are instructed to install a Google Chrome update patch to access the site. If they do, a malicious ZIP file is downloaded on their device. The ZIP file contains a Monero cryptominer malware.
While cryptominers may not steal your data or target your files, they can burden your system. Cryptominers can overheat your devices and destroy computer components, especially if you don’t have an adequate cooling mechanism. Users may notice performance lags as well as higher power and data consumption.
According to Koike, the malware used in this campaign is not a basic cryptominer. It modifies Windows Defender and other antivirus software on the target’s device to evade detection. It also stops Windows Update and modifies other system settings.
Protecting Your System From Cryptominers
In November 2022, Kaspersky’s SecureList lab revealed that cryptominer malware infections peaked in the first quarter of 2022, with over 500,000 users affected. Unlike other malicious schemes, cryptominers offer cybercriminals instant monetary rewards.
Cryptominer infections have become increasingly common. In recent years, U.S. federal agencies and supercomputers across Europe have been targeted with cryptominers.
According to U.S. cybersecurity giant Palo Alto Networks, cryptominers come in two forms. The first is browser-based and is only active when victims visit a compromised webpage. The other can “take over your entire computer and use the computer CPU at a much higher level.”
To protect your system from cryptominers, keep your apps updated and only get updates from official sources. Set your device to receive updates automatically. Most importantly, use a top-rated antivirus solution to defend your system. Check out our ratings of the best antivirus software for some suggestions.
