Beware – Trojan Alert – Fake Google Chrome Extension

by Dinu on 20/04/2010



Fake Google Chrome Extension  Trojan

With more and more people reaching the web through Google Chrome, hackers and spammers have started targeting Google Chrome too.  Google Chrome have been proved as the most secure browser. Now, they are trying to hack you through extension system, or faking itself as a extension.

Malwarecity.com reports a new trojan that fakes itself as a Google Chrome extension. “The story is simple: Google Chrome users receive an unsolicited e-mail which announces that a new extension of their favorite browser has been developed to facilitate their access to documents from e-mails”. they wrote.

How to Identify

If you have noticed, Google Chrome extensions are always .crx files. And this trojan, is a .exe file. So,be careful with  anything that calls itself a chrome extension and is not .crx file.

What It Does

It modifies the Windows HOSTS file in an attempt to block access to Google and Yahoo webpages. Every time users want to access them and write “google.[xxx]” or “[xx].search.yahoo.com” in the web browser, they will be redirected to another IP:  89.149.xxx.xxx . This allows the malware creators to intercept the victims’ calls to reach the respective sites.

The Ultimate Solution

It’s simple ! Install extensions only from Google’s Official Extensions gallery.

source

Related posts:

  1. SpyEye Trojan Now Targets Google Chrome #Security Online marketing and  Trojan attacks have one thing in common. They tend to move towards corners of the web where more users are available for...
  2. How to Write an extension to modify a website for chrome This is a guest gust post by Geek107. He explains how to Write an extension to modify a website for chrome Ok, if you’re a web developer,...
  3. “Extensions” – Let this be your first Chrome Extension If you start playing around with Google Chrome Extensions, you will end up installing many extensions, like me. Each time you need to change something...

{ 3 comments… read them below or add one }

Haresh April 20, 2010 at 3:32 pm

If it’s not an extension and doesn’t have .crx extension, why do you refer to it as an extension. It is misleading.

Reply

chrome story April 20, 2010 at 5:12 pm

the email will say it is an extension. You will download the file from a page that looks like the normal extensions gallery.

this is enough for a normal user to think that its an extension. they may not check the file extension like geeks ;)

Reply

Haresh April 25, 2010 at 12:08 am

hmm… makes sense :D

Reply

Leave a Comment

Previous post:

Next post: