Categories: InternetSecurity News

More than 20,000,000 Chrome Users are Tricked into Installing Fake Ad Blockers

Nowadays adblockers are quite popular among user’s, but before installing extension it is required to make validation checks to ensure that you are installing the trusted extension, else you may end up with Fake Ad Blockers.

Cloning the famous and wide-spread extension is not new, but instead of using tricky names attackers started using keywords with the extension description and trying to make the top of the search results.

Andrey Meshkov from Adguard reports that attackers tricked more than 20,000,000 users to install the fake extension of the ad blockers.

I must say the problem is not new. It’s been a while since different “authors” started spamming Chrome WebStore with lazy clones of popular ad blockers and the only way to stop is by filing a violation abuse to Google to Google and it takes couple day’s to turn down the app.

Casual user’s use to believe in the top search results which are not good, a deeper analysis is required before selecting an extension that serves our purpose.

What these Fake Ad Blockers Do

They found to be hidden inside of well-known javascript files and they track the user activities such as the pages that you are visiting and send’s the information to the attacker’s server.

Fake Ad Blockers.Fake Ad Blockers.

To avoid detection they use to transfer the harmful codes inside of the legitimate image files which later executed in browser background and can change your browser behavior in any way.

This is not a first time, few months before Google Taken Down More than 423,992 users have been affected with the bot and a total of 89 extensions removed from chrome web store.

Here is the full list of the extensions identified by Adguard on WebStore

AdRemover for Google Chrome™ (10M+ users)
uBlock Plus (8M+ users)
Adblock Pro (2M+ users)
HD for YouTube™ (400K+ users)
Webutation (30K+ users)

All the apps has been reported to the Google and all the five apps are taken down.

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Secure Ideas Achieves CREST Accreditation and CMMC Level 1 Compliance

Secure Ideas, a premier provider of penetration testing and security consulting services, proudly announces its…

9 hours ago

New Phishing Campaign Targets Investors to Steal Login Credentials

Symantec has recently identified a sophisticated phishing campaign targeting users of Monex Securities (マネックス証券), a…

10 hours ago

UAC-0219 Hackers Leverage WRECKSTEEL PowerShell Stealer to Extract Data from Computers

In a concerning development, CERT-UA, Ukraine's Computer Emergency Response Team, has reported a series of…

10 hours ago

Hunters International Linked to Hive Ransomware in Attacks on Windows, Linux, and ESXi Systems

Hunters International, a ransomware group suspected to be a rebrand of the infamous Hive ransomware,…

10 hours ago

Qilin Operators Imitate ScreenConnect Login Page to Deploy Ransomware and Gain Admin Access

In a recent cyberattack attributed to the Qilin ransomware group, threat actors successfully compromised a…

10 hours ago

Operation HollowQuill Uses Malicious PDFs to Target Academic and Government Networks

A newly uncovered cyber-espionage campaign, dubbed Operation HollowQuill, has been identified as targeting academic, governmental,…

10 hours ago