This Windows malware uses PowerShell to inject malicious extension into Chrome
- Reference: 1653650769
- News link: https://www.theregister.co.uk/2022/05/27/chromeloader-malware-powershell/
- Source link:
The makers of the ChromeLoader software nasty ensure their malware is persistent once on a system and is difficult to find and remove, according to threat hunters at cybersecurity shop Red Canary, who have been tracking the strain since early February and have seen a flurry of recent activity.
"We first encountered this threat after detecting encoded PowerShell commands referencing a scheduled task called 'ChromeLoader' – and only later learned that we were catching ChromeLoader in the middle stage of its deployment," Aedan Russell, detection engineer at Red Canary, wrote in a [1]blog post this week.
[2]
The malicious extension injected by ChromeLoader is designed, once added to a victim's browser, to redirect the user through online adverts, triggering revenue for miscreants. The Windows ChromeLoader's use of PowerShell to drop in more malicious Chrome extensions is uncommon, Russell told The Register .
[3]
[4]
"ChromeLoader's developer has found an efficient means of collecting ad revenue by using a legitimate developer command line argument for Chrome," he said.
"Loading a web browser extension via PowerShell (and doing so silently) shows a level of stealthiness above the norm as other malicious browser extensions are usually introduced by tricking the user into overtly installing them, often posing as legitimate browser extensions."
[5]
Red Canary isn't the only threat intelligence group to get onto ChromeLoader. Researchers at G-Data CyberDefense in February wrote [6]a blog post about the malware, dubbing it Choziosi loader, that also talked about using the PowerShell script.
In addition, threat researcher Colin Cowie [7]wrote about the aforementioned variant of ChromeLoader targeting Macs in April.
ChromeLoader gets initial access into a system by being distributed as an ISO file that looks like a torrent or a cracked video game. It is spread via pay-per-install sites and social media networks like Twitter, according to Red Canary.
[8]
"Once downloaded and executed, the .ISO file is extracted and mounted as a drive on the victim's machine," Russell wrote of the Windows version. "Within this ISO is an executable used to install ChromeLoader, along with what appears to be a .NET wrapper for the Windows Task Scheduler. This is how ChromeLoader maintains its persistence on the victim's machine later in the intrusion chain."
The persistence is gained through a scheduled task using the Service Host Process, though the malware does not use the Windows Task Scheduler to add the task.
[9]Suspected phishing email crime boss cuffed in Nigeria
[10]Ransomware grounds some flights at Indian budget airline SpiceJet
[11]Millions of people's info stolen from MGM Resorts dumped on Telegram for free
[12]How these crooks backdoor online shops and siphon victims' credit card info
"While not using groundbreaking techniques, ChromeLoader has found success in its stealthier persistence mechanisms," Russell told The Register .
"It uses a scheduled task, but not by using the Windows native Task Scheduler (schtasks.exe) to do so. Instead, ChromeLoader creates its scheduled task via injection into the Service Host (svchost.exe), using functionality from an imported Task Scheduler COM API."
Once the scheduled task executes PowerShell and loads the extension, it is silently removed with the PowerShell module invoke schtasks.exe and is often less frequently monitored as an anti-forensic technique, according to Russell.
"This is a novel method for loading a malicious extension into Chrome that I have not seen before, nor has it been observed by Red Canary's intelligence team in other malware," he said.
"While other bad actors could capitalize on this method, they still need to place a portable executable on the victim machine to ultimately use the load-extension PowerShell technique."
While ChromeLoader used disguised ISO files to deliver it, many enterprises are now monitoring or blocking ISOs from the internet because they are popular ways to deliver other malware. If a bad actor determines that ChromeLoader's method is effective for loading a malicious extension, they will likely use it, he said.
In addition, because of its capabilities as a command and scripting interpreter, PowerShell will always be a top command-execution method for threat actors.
"In the particular case of ChromeLoader, the overall impact appears to be relatively low since the malware has only been observed redirecting user traffic to spam sites," Russell said. "There are no known attempts by threat actors to load malicious browser extensions using this PowerShell technique, outside of ChromeLoader.
"However, this technique is well documented and used by developers quite often." ®
Get our [13]Tech Resources
[1] https://redcanary.com/blog/chromeloader/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YpD1oI-gZffeOXjSdu4LAgAAAAQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YpD1oI-gZffeOXjSdu4LAgAAAAQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YpD1oI-gZffeOXjSdu4LAgAAAAQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YpD1oI-gZffeOXjSdu4LAgAAAAQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.gdatasoftware.com/blog/2022/01/37236-qr-codes-on-twitter-deliver-malicious-chrome-extension
[7] https://www.th3protocol.com/2022/Choziosi-Loader
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YpD1oI-gZffeOXjSdu4LAgAAAAQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2022/05/26/nigerian_phishing_arrest/
[10] https://www.theregister.com/2022/05/26/ransomware_attack_grounds_spicejet/
[11] https://www.theregister.com/2022/05/25/mgm_customers_data_dumped_again/
[12] https://www.theregister.com/2022/05/18/fbi_credit_card/
[13] https://whitepapers.theregister.com/
Re: Weird first sentence?
"strain of windows" sounds about right, to me ;p
More of the usual
" ChromeLoader creates its scheduled task via injection into the Service Host (svchost.exe), using functionality from an imported Task Scheduler COM API "
Typical Borkzilla. More full of holes than Swiss cheese.
Re: More of the usual
Sounds a lot like you need to run that "game" (that you downloaded from a dodgy web site) as an admin. If so, I hardly think it counts as a hole. I could "inject" malware into crontab on a Linux system if I had the privileges. It's what the damn thing is designed for!
It is fun to see different examples of the mischief that people can get up to once they've taken over your system and it gives us more examples to use to convince our friends that they really shouldn't be running anything as admin if they can possibly avoid it, and certainly not if they've got it from a "helpful" site that meant they didn't have to pay for it. But it is hardly news.
How about a new OS?
"Windows" are normally easily opened for the fresh air and insects to fly though the room, maybe we should switch to a new OS called "Stonewall"?
Modern things are designed to be easy to use, that's far more important to the creators than stone wall security. So nothing much is going to change until we create a new OS that is totally secure, maybe it will be hard to add the modern "easy to use" features but I think that safer to use is where we need to head to these days.
Re: How about a new OS?
The totally secure OS is a myth, because people. Even an embedded, off network system usually have some means of personnel interaction at some level. And it might not be so off network as you thought.
Checks and balances; multiple layers, audit and penetration testing are necessary to stay on top of ones game. Changing personnel and skillsets doing those tasks is also recommended.
This is paranoid, but working on the assumption that everything either is, or will be broken in your tenure is a necessary evil when you actually do have something worth securing to that extent.
In consumer OS land; WIndows, Apple, Android or iOS; basically you're screwed. So don't put material you care about securing on them. (Some variants are better than others - but none by any means ideal).
Weird first sentence?
a strain of Windows?? No, I haven't been round the pub... yet! Maybe a strain of Malware? But perhaps you're right!