Home » Security News » Chaes banking trojan is being served by malicious ...

Chaes banking trojan is being served by malicious Chrome extensions

Chaes banking trojan is being served by malicious Chrome extensions
Deepanker Verma January 27, 2022 Security

Add Techlomedia as a preferred source on Google. Preferred Source

Cybercriminals are using over 800 compromised WordPress websites to spread Chaes banking trojan. This Trojan steals the login credentials of e-banking users.

Researchers from Avast found that Chaes banking Trojan has been actively spreading since late 2021. It primarily targeted Brazilian e-banking users. The security firm also notified the Brazilian CERT.

When a user visits any of the compromised websites, it will show a pop-up requesting to install a fake Java Runtime app. This installer includes three malicious JavaScript files (install.js, sched.js, sucesso.js). These files prepare the base for further attack.

Here’s a photo explaining the infection chain.

Chaes banking trojan

After the successful installation of the Trojan on compromised systems, all web credentials, history, user profiles stored by Chrome will be sent to attackers. Here is the list of banking websites are being targeted.

  • mercadobitcoin.com.br
  • mercadopago.com.[ar|br]
  • mercadolivre.com.br
  • lojaintegrada.com.br

The company also found 5 different malicious Chrome browser extensions installed on the victim’s devices. These extensions serve different purposes.

  • Online – Fingerprints the victim and writes a registry key.
  • Mtps4 – Connects to the C2 and waits for incoming PascalScripts.
  • Chrolog – Steals passwords from Google Chrome.
  • Chronodx – A loader and JS banking trojan that runs silently in the background.
  • Chremows – Targets Mercado Libre online marketplace credentials.

The security firm noted that the attack is still on and people whose systems have been compromised are still at the risk. The number of infected systems is likely large.

Follow Techlomedia on Google News to stay updated. Follow on Google News

Affiliate Disclosure:

This article may contain affiliate links. We may earn a commission on purchases made through these links at no extra cost to you.

Deepanker Verma

About the Author: Deepanker Verma

Deepanker Verma is the Founder and Editor-in-Chief of TechloMedia. He holds Engineering degree in Computer Science and has over 15 years of experience in the technology sector. Deepanker bridges the gap between complex engineering and consumer electronics. He is also a a known Security Researcher acknowledged by global giants including Apple, Microsoft, and eBay. He uses his technical background to rigorously test gadgets, focusing on performance, security, and long-term value.

Related Posts

Stay Updated with Techlomedia

Join our newsletter to receive the latest tech news, reviews, and guides directly in your inbox.