A new malware campaign propagating via crafted socially-engineered links on Facebook abuses the users by installing a malicious chrome extension and performs crypto mining, click fraud, Password theft and more.
Facebook Malware campaigns are not new, this new campaign Modus operandi is same as like any other previous malware campaigns.
Radware’s Threat Research team revealed that this group is active since at least March of 2018 and it infects more than 100,000 users in about more than 100 countries. The sophisticated group remains undetected until now as they keep on changing their mechanism for malware distribution.
The malware dubbed Nigelthorn spreads at a rapid pace, it redirects users to the fake youtube page and forces to install the Chrome extension to play the video.
Once the user click’s on Add Extension then the malicious extension will be installed and now the machine is a part of the bot and it is compatible with both Windows and Linux.
According to Radware ” Over 75% of the infections cover the Philippines, Venezuela, and Ecuador. The remaining 25% are distributed over 97 other countries”.
The campaign abuses the legitimate Nigelify application and inserts the malicious script to start the malware campaign.
Radware team observed seven of such malicious extensions and four of them already blocked by Google’s security algorithms.
Once the malware installed it establishes the connection with C&C server to download the required malicious JavaScript.
The malware mainly focused on extracting Facebook login credentials and Instagram cookies. Another plugin that downloaded by malware generates cryptocurrencies, Radware observed the group tried mining different coins based on the CryptoNight algorithm (Monero, Bytecoin, and Electroneum).
As like any other malware, it tries it’s best to remain persistent by preventing the victims removing the malicious extension. If it detects victims opening the chrome extension management “chrome://extensions/” then it closes the page immediately.
PortSwigger released a brand-new version of Burp Suite 2023.6 that is intended for both Professional…
The North Korean APT group Kimsuky has been running a social engineering operation that targets experts…
Recently, cybersecurity researchers uncovered that over 60,000 Android applications had been stealthily disguised as genuine…
Google has recently taken prompt security measures by releasing a security update for its Chrome…
A major MOVEit Hack has impacted many businesses, notably the BBC, British Airways, Boots, and…
A Vulnerability Scanner Tools is one of the essential tools in IT departments Since vulnerabilities…