VOOZH about

URL: https://thehackernews.com/2022/05/experts-warn-of-rise-in-chromeloader.html

⇱ Experts Warn of Rise in ChromeLoader Malware Hijacking Users' Browsers


-->
πŸ‘ cybersecurity

Experts Warn of Rise in ChromeLoader Malware Hijacking Users' Browsers

ξ „Ravie Lakshmananξ ‚May 26, 2022

A malvertising threat is witnessing a new surge in activity since its emergence earlier this year.

Dubbed ChromeLoader, the malware is a "pervasive and persistent browser hijacker that modifies its victims' browser settings and redirects user traffic to advertisement websites," Aedan Russell of Red Canary said in a new report.

ChromeLoader is a rogue Chrome browser extension and is typically distributed in the form of ISO files via pay-per-install sites and baited social media posts that advertise QR codes to cracked video games and pirated movies.

While it primarily functions by hijacking user search queries to Google, Yahoo, and Bing and redirecting traffic to an advertising site, it's also notable for its use of PowerShell to inject itself into the browser and get the extension added.

The malware, also known as Choziosi Loader, was first documented by G DATA earlier this February.

"For now the only purpose is getting revenue via unsolicited advertisements and search engine hijacking," G DATA's Karsten Hahn said. "But loaders often do not stick to one payload in the long run and malware authors improve their projects over time."

Another trick up ChromeLoader's sleeve is its ability to redirect victims away from the Chrome extensions page ("chrome://extensions") should they attempt to remove the add-on.

Furthermore, researchers have detected a macOS version of the malware that works against both Chrome and Safari browsers, effectively turning ChromeLoader into a cross-platform threat.

"If applied to a higher-impact threat β€” such as a credential harvester or spyware β€” this PowerShell behavior could help malware gain an initial foothold and go undetected before performing more overtly malicious activity, like exfiltrating data from a user's browser sessions," Russell noted.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
⚑ Top Stories This Week
⭐ Featured Resources

Cybersecurity Webinars

A Practical Security Guide

How to Find and Govern Hidden AI Use Across Your Business

Learn how to uncover hidden AI use, see what data it can access, map every AI action to a human owner, and apply practical governance without heavy infrastructure changes.

Tired of False Positives?

How to Stop AI-Powered Attacks Before They Move Across Your Network

Learn how to contain Mythos-style AI attacks with practical Zero Trust controls that reduce exposure, stop lateral movement, and limit risk.

⚑ Latest News
Cybersecurity Resources
5 Steps to Secure Against Software Vulnerabilities Discovered by AI Models
AI has emerged as a potent weapon in cybersecurity. Learn how to best safeguard your organization.
The CISO’s Guide: Transitioning from VPN to Comprehensive ZTNA
Modernize secure access and eliminate lateral movement by connecting users directly to applications, not the network.
Earn a Master's in Cybersecurity Risk Management
Lead the future of cybersecurity risk management with an online Master’s from Georgetown.
​
Expert Insights Articles Videos
πŸ‘ Expert Insights

Building a Security Strategy for AI-Powered Ransomware Attacks

ξ ‚June 22, 2026 Read ➝
πŸ‘ Expert Insights

Identity Security in 2026: The Brutal Truth Enterprises Still Avoid

ξ ‚June 22, 2026 Read ➝
πŸ‘ Expert Insights

Beyond Blocking: Disrupting the Social Engineering Attack Chain

ξ ‚June 22, 2026 Read ➝
πŸ‘ Expert Insights

Why Runtime Scanning Is Too Late for Your CI/CD Supply Chain Security

ξ ‚June 15, 2026 Read ➝