TheCitizen - It's all about you
  • Home
  • Headlines
  • Latest News
  • Governance
  • Business
  • Financial Crimes
  • Opinion
  • Editorials
No Result
View All Result
  • Home
  • Headlines
  • Latest News
  • Governance
  • Business
  • Financial Crimes
  • Opinion
  • Editorials
No Result
View All Result
TheCitizen - It's all about you
No Result
View All Result

ChromeLoader malware campaign punishes pirating users – HP warns

The Editor by The Editor
June 16 2023
in Business
A A
0
ChromeLoader malware campaign punishes pirating users – HP warns

HP has issued its quarterly HP Wolf Security Threat Insights Report, showing threat actors are hijacking users’ Chrome browsers if they try to download popular movies or video games from pirating websites.

By isolating threats that have evaded detection tools on PCs, HP Wolf Security has specific insight into the latest techniques being used by cybercriminals in the fast-changing cybercrime landscape. To date, HP Wolf Security customers have clicked on over 30 billion email attachments, web pages, and downloaded files with no reported breaches.

Based on data from millions of endpoints running HP Wolf Security, the researchers found:

  • The Shampoo Chrome extension is hard to wash out: A campaign distributing the ChromeLoader malware tricks users into installing a malicious Chrome extension called Shampoo. It can redirect the victim’s search queries to malicious websites, or pages that will earn the criminal group money through ad campaigns. The malware is highly persistent, using Task Scheduler to re-launch itself every 50 minutes. 
  • Attackers bypass macro policies by using trusted domains: While macros from untrusted sources are now disabled, HP saw attackers bypass these controls by compromising a trusted Office 365 account, setting up a new company email, and distributing a malicious excel file that infects victims with the Formbook infostealer.
  • Firms must beware of what lurks beneath: OneNote documents can act as digital scrapbooks, so any file can be attached within. Attackers are taking advantage of this to embed malicious files behind fake “click here” icons. Clicking the fake icon opens the hidden file, executing malware to give attackers access to the users’ machine – this access can then be sold on to other cybercriminal groups and ransomware gangs.

Sophisticated groups like Qakbot and IcedID first embedded malware into OneNote files in January. With OneNote kits now available on cybercrime marketplaces and requiring little technical skill to use, their malware campaigns look set to continue over the coming months.

“To protect against the latest threats, we advise that users and businesses avoid downloading materials from untrusted sites, particularly pirating sites. Employees should be wary of suspicious internal documents and check with the sender before opening. Organizations should also configure email gateway and security tool policies to block OneNote files from unknown external sources,” explainsPatrick Schläpfer, Malware Analyst at the HP Wolf Security threat research team, HP Inc.

From malicious archive files to HTML smuggling, the report also shows cybercrime groups continue to diversify attack methods to bypass email gateways, as threat actors move away from Office formats. Key findings include:

  • Archives were the most popular malware delivery type (42%) for the fourth quarter running when examining threats stopped by HP Wolf Security in Q1.
  • There was a 37-percentage-point rise in HTML smuggling threats in Q1 versus Q4.
  • There was a 4-point rise in PDF threats in Q1 versus Q4.
  • There was a 6-point drop in Excel malware (19% to 13%) in Q1 versus Q4, as the format has become more difficult to run macros in.
  • 14% of email threats identified by HP Sure Click bypassed one or more email gateway scanner in Q1 2023.
  • The top threat vector in Q1 was email (80%) followed by browser downloads (13%).

“To protect against increasingly varied attacks, organizations must follow zero trust principles to isolate and contain risky activities such as opening email attachments, clicking on links, or browser downloads. This greatly reduces the attack surface along with the risk of a breach,” comments Dr. Ian Pratt, Global Head of Security for Personal Systems, HP Inc.

HP Wolf Security runs risky tasks like opening email attachments, downloading files and clicking links in isolated, micro-virtual machines (micro-VMs) to protect users. It also captures detailed traces of attempted infections. HP’s application isolation technology mitigates threats that might slip past other security tools and provides unique insights into novel intrusion techniques and threat actor behavior.

Previous Post

Hilton announces signing of Koko Beach Resort Ilashe Lagos, Curio Collection by Hilton

Next Post

Akpabio in Enugu, seeks partnership with Mbah’s led administration on good governance

Related Posts

Egbin Power fuels performance culture, honours outstanding employees, talents at ERA 2026
Business

Egbin Power fuels performance culture, honours outstanding employees, talents at ERA 2026

June 3 2026
Private sector faults N100,000 minimum wage proposal
Business

Private sector faults N100,000 minimum wage proposal

June 3 2026
FG, Discos to sign fresh performance agreement on power
Business

Discos earn N600bn in three months despite blackouts

June 3 2026
Food prices record month-on-month increases
Business

Food prices record month-on-month increases

June 2 2026
Supreme Court sanctions Providus–Unity Bank merger
Business

Supreme Court sanctions Providus–Unity Bank merger

June 2 2026
Nigerians need affordable fuel – Punch
Business

Petrol price soars 643% in three years

June 2 2026
Next Post
Akpabio in Enugu, seeks partnership with Mbah’s led administration on good governance

Akpabio in Enugu, seeks partnership with Mbah’s led administration on good governance

Kano naval base project wasteful, counter-productive – Security experts

DHQ, Asari trades words over oil theft

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

FROM THE GRASSROOTS

Ondo LG shuts schools over security concerns

Ondo LG shuts schools over security concerns

by The Editor
June 2 2026
0

...

IPOB hails observance of Biafra Heroes Remembrance Day

IPOB hails observance of Biafra Heroes Remembrance Day

by The Editor
May 31 2026
0

...

Alaafin urges FG to strengthen native intelligence after Oyo school attacks

Alaafin urges FG to strengthen native intelligence after Oyo school attacks

by The Editor
May 17 2026
0

...

Gov. Adeleke deposes Oba Joseph Oloyede, Apetu of Ipetumodu

Gov. Adeleke deposes Oba Joseph Oloyede, Apetu of Ipetumodu

by The Editor
May 12 2026
0

...

APPOINTMENTS

Botswana appoints Nigerian Adesina as Chair of Diamonds for Development Fund

Botswana appoints Nigerian Adesina as Chair of Diamonds for Development Fund

by The Editor
June 3 2026
0

...

Elumelu joins Seplat board after $496m share acquisition

Elumelu joins Seplat board after $496m share acquisition

by The Editor
May 21 2026
0

...

Tinubu appoints 39-year-old Prof as new JAMB registrar

Tinubu appoints 39-year-old Prof as new JAMB registrar

by The Editor
May 21 2026
0

...

Soludo reshuffles power structure, swears in 18 Commissioners

Soludo reshuffles power structure, swears in 18 Commissioners

by The Editor
May 18 2026
0

...

ODDITIES

Man dies after torture by So-Safe officers in Ogun

Man dies after torture by So-Safe officers in Ogun

by The Editor
June 2 2026
0

FUTO student dies in Man O’ War custody, police arrest three suspects

FUTO student dies in Man O’ War custody, police arrest three suspects

by The Editor
May 31 2026
0

Bus driver stabs transport officer to death in Calabar

Bus driver stabs transport officer to death in Calabar

by The Editor
May 26 2026
0

GLOBAL NEWS

Iran hits US Fifth Fleet HQ, airbase after violations near Strait of Hormuz

Iran hits US Fifth Fleet HQ, airbase after violations near Strait of Hormuz

by The Editor
June 3 2026
0

...

Kuwait suspends flights after Iran strikes airport

Kuwait suspends flights after Iran strikes airport

by The Editor
June 3 2026
0

...

Protesting teachers in Mexico topple player statues days before World Cup

Protesting teachers in Mexico topple player statues days before World Cup

by The Editor
June 3 2026
0

...

Zimbabwe considers controversial presidential term-extension bill

Zimbabwe considers controversial presidential term-extension bill

by The Editor
June 2 2026
0

...

US cuts visa processing centres in Africa

US cuts visa processing centres in Africa

by The Editor
June 2 2026
0

...

State of the States

Abia launches bid for UNESCO Creative City Status for Aba, plans 1929 Women Riot honour

Abia launches bid for UNESCO Creative City Status for Aba, plans 1929 Women Riot honour

by The Editor
June 3 2026
0

...

Gov. Adeleke deposes Oba Joseph Oloyede, Apetu of Ipetumodu

Gov. Adeleke mobilises hunters, security forces to protect Osun schools, communities

by The Editor
June 2 2026
0

...

Hoodlums attack Soludo’s Chief of Staff convoy, kill two policemen

Hoodlums attack Soludo’s Chief of Staff convoy, kill two policemen

by The Editor
June 1 2026
0

...

Amotekun Corps loses 200 operatives in battle against insecurity in Oyo

Amotekun Corps loses 200 operatives in battle against insecurity in Oyo

by The Editor
June 1 2026
0

...

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
World Bicycle Day 2026: BrandEscort reaffirms commitment to promoting greener future through Cycling Lagos, Cycling Kano

World Bicycle Day 2026: BrandEscort reaffirms commitment to promoting greener future through Cycling Lagos, Cycling Kano

June 3 2026
Egbin Power fuels performance culture, honours outstanding employees, talents at ERA 2026

Egbin Power fuels performance culture, honours outstanding employees, talents at ERA 2026

June 3 2026
Iran hits US Fifth Fleet HQ, airbase after violations near Strait of Hormuz

Iran hits US Fifth Fleet HQ, airbase after violations near Strait of Hormuz

June 3 2026
Gunmen kidnap ex-minister Adelabu’s sister, children in Ibadan

Gunmen kidnap ex-minister Adelabu’s sister, children in Ibadan

June 3 2026

EDITORIAL REVIEW

Cooking gas price hike deepens Nigerians’ woes – Punch

Cooking gas price hike deepens Nigerians’ woes – Punch

by The Editor
June 3 2026
0

Nigeria’s obscene money politics – Punch

Nigeria’s obscene money politics – Punch

by The Editor
June 2 2026
0

The $498.8m fund to fight Ebola – Vanguard

The $498.8m fund to fight Ebola – Vanguard

by The Editor
June 1 2026
0

Tinubu denies Christian, Muslim genocide in Nigeria

Three years of Tinubu reforms – Punch

by The Editor
June 1 2026
0

Children’s Day of gloom – Punch

Children’s Day of gloom – Punch

by The Editor
May 31 2026
0

Opinion

Of bandits and their informants/sponsors

Of bandits and their informants/sponsors

by The Editor
June 1 2026
0

...

Nigeria at critical juncture – Vanguard

Nigerian economy: The street is not smiling!

by The Editor
June 1 2026
0

...

Tinubu sticking to anti-masses policy, says Afenifere

As criminals seize Nigerian babies

by The Editor
May 31 2026
0

...

School attacks and the death of ethics

School attacks and the death of ethics

by The Editor
May 22 2026
0

...

Plugin Install : Popular Post Widget need JNews - View Counter to be installed
  • Home
  • Headlines
  • Latest News
  • Governance
  • Business
  • Financial Crimes
  • Opinion
  • Editorials

© 2026 TheCitizen Ng. All Rights Reserved.

No Result
View All Result
  • Home
  • Headlines
  • Latest News
  • Governance
  • Business
  • Financial Crimes
  • Opinion
  • Editorials

© 2026 TheCitizen Ng. All Rights Reserved.