Site icon TechloMedia

Chaes banking trojan is being served by malicious Chrome extensions

Ransomware

Cybercriminals are using over 800 compromised WordPress websites to spread Chaes banking trojan. This Trojan steals the login credentials of e-banking users.

Researchers from Avast found that Chaes banking Trojan has been actively spreading since late 2021. It primarily targeted Brazilian e-banking users. The security firm also notified the Brazilian CERT.

When a user visits any of the compromised websites, it will show a pop-up requesting to install a fake Java Runtime app. This installer includes three malicious JavaScript files (install.js, sched.js, sucesso.js). These files prepare the base for further attack.

Here’s a photo explaining the infection chain.

After the successful installation of the Trojan on compromised systems, all web credentials, history, user profiles stored by Chrome will be sent to attackers. Here is the list of banking websites are being targeted.

The company also found 5 different malicious Chrome browser extensions installed on the victim’s devices. These extensions serve different purposes.

The security firm noted that the attack is still on and people whose systems have been compromised are still at the risk. The number of infected systems is likely large.

Exit mobile version