TheCitizen - It's all about you
  • Home
  • Headlines
  • Latest News
  • Governance
  • Business
  • Financial Crimes
  • Opinion
  • Editorials
No Result
View All Result
  • Home
  • Headlines
  • Latest News
  • Governance
  • Business
  • Financial Crimes
  • Opinion
  • Editorials
No Result
View All Result
TheCitizen - It's all about you
No Result
View All Result

ChromeLoader malware campaign punishes pirating users – HP warns

The Editor by The Editor
June 16, 2023
in Business
A A
0
ChromeLoader malware campaign punishes pirating users – HP warns
23
SHARES
752
VIEWS
Share on FacebookShare on Twitter

HP has issued its quarterly HP Wolf Security Threat Insights Report, showing threat actors are hijacking users’ Chrome browsers if they try to download popular movies or video games from pirating websites.

By isolating threats that have evaded detection tools on PCs, HP Wolf Security has specific insight into the latest techniques being used by cybercriminals in the fast-changing cybercrime landscape. To date, HP Wolf Security customers have clicked on over 30 billion email attachments, web pages, and downloaded files with no reported breaches.

Based on data from millions of endpoints running HP Wolf Security, the researchers found:

  • The Shampoo Chrome extension is hard to wash out: A campaign distributing the ChromeLoader malware tricks users into installing a malicious Chrome extension called Shampoo. It can redirect the victim’s search queries to malicious websites, or pages that will earn the criminal group money through ad campaigns. The malware is highly persistent, using Task Scheduler to re-launch itself every 50 minutes. 
  • Attackers bypass macro policies by using trusted domains: While macros from untrusted sources are now disabled, HP saw attackers bypass these controls by compromising a trusted Office 365 account, setting up a new company email, and distributing a malicious excel file that infects victims with the Formbook infostealer.
  • Firms must beware of what lurks beneath: OneNote documents can act as digital scrapbooks, so any file can be attached within. Attackers are taking advantage of this to embed malicious files behind fake “click here” icons. Clicking the fake icon opens the hidden file, executing malware to give attackers access to the users’ machine – this access can then be sold on to other cybercriminal groups and ransomware gangs.

Sophisticated groups like Qakbot and IcedID first embedded malware into OneNote files in January. With OneNote kits now available on cybercrime marketplaces and requiring little technical skill to use, their malware campaigns look set to continue over the coming months.

“To protect against the latest threats, we advise that users and businesses avoid downloading materials from untrusted sites, particularly pirating sites. Employees should be wary of suspicious internal documents and check with the sender before opening. Organizations should also configure email gateway and security tool policies to block OneNote files from unknown external sources,” explainsPatrick Schläpfer, Malware Analyst at the HP Wolf Security threat research team, HP Inc.

From malicious archive files to HTML smuggling, the report also shows cybercrime groups continue to diversify attack methods to bypass email gateways, as threat actors move away from Office formats. Key findings include:

  • Archives were the most popular malware delivery type (42%) for the fourth quarter running when examining threats stopped by HP Wolf Security in Q1.
  • There was a 37-percentage-point rise in HTML smuggling threats in Q1 versus Q4.
  • There was a 4-point rise in PDF threats in Q1 versus Q4.
  • There was a 6-point drop in Excel malware (19% to 13%) in Q1 versus Q4, as the format has become more difficult to run macros in.
  • 14% of email threats identified by HP Sure Click bypassed one or more email gateway scanner in Q1 2023.
  • The top threat vector in Q1 was email (80%) followed by browser downloads (13%).

“To protect against increasingly varied attacks, organizations must follow zero trust principles to isolate and contain risky activities such as opening email attachments, clicking on links, or browser downloads. This greatly reduces the attack surface along with the risk of a breach,” comments Dr. Ian Pratt, Global Head of Security for Personal Systems, HP Inc.

HP Wolf Security runs risky tasks like opening email attachments, downloading files and clicking links in isolated, micro-virtual machines (micro-VMs) to protect users. It also captures detailed traces of attempted infections. HP’s application isolation technology mitigates threats that might slip past other security tools and provides unique insights into novel intrusion techniques and threat actor behavior.

Share9Tweet6
Previous Post

Hilton announces signing of Koko Beach Resort Ilashe Lagos, Curio Collection by Hilton

Next Post

Akpabio in Enugu, seeks partnership with Mbah’s led administration on good governance

Related Posts

BUA slashes cement price to N3,500
Business

BUA slashes cement price to N3,500

October 2, 2023
Lagos begins market demolition at train station locations
Business

Lagos begins market demolition at train station locations

October 1, 2023
Savannah Energy announces 2023 half-year results with 12% increase in Nigerian production
Business

Savannah Energy announces 2023 half-year results with 12% increase in Nigerian production

September 30, 2023
MediaCraft Associates launches PR Academy
Business

Mediacraft Associates celebrates 20th Anniversary, increases staff salaries 

September 30, 2023
For LAPO MFB, sustainability is not just a slogan, it is a lifestyle
Business

For LAPO MFB, sustainability is not just a slogan, it is a lifestyle

September 30, 2023
LIRS tasks business organizations on consumption tax compliance
Business

LIRS tasks business organizations on consumption tax compliance

September 29, 2023
Next Post
Akpabio in Enugu, seeks partnership with Mbah’s led administration on good governance

Akpabio in Enugu, seeks partnership with Mbah’s led administration on good governance

Kano naval base project wasteful, counter-productive – Security experts

DHQ, Asari trades words over oil theft

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

FROM THE GRASSROOTS

Ondo senator appoints 100 PAs, awards N300k to each constituent

Ondo senator appoints 100 PAs, awards N300k to each constituent

by The Editor
September 20, 2023
0

...

Obasanjo laments insecurity on Nigeria roads, railways, airports

Yoruba Obas Forum insists on Obasanjo’s public apology

by The Editor
September 19, 2023
0

...

Cult clash: Sagamu LG imposes dusk-to-dawn curfew on motorcycle, tricycle operations

Cult clash: Sagamu LG imposes dusk-to-dawn curfew on motorcycle, tricycle operations

by The Editor
September 18, 2023
0

...

Rivers council boss bans commercial tricycle operations over insecurity

Rivers council boss bans commercial tricycle operations over insecurity

by The Editor
September 16, 2023
0

...

APPOINTMENTS

Biden appoints two Nigerians, Imasogie, Ogwumike as advisers

Biden appoints two Nigerians, Imasogie, Ogwumike as advisers

by The Editor
September 28, 2023
0

...

Tinubu nominates Cardoso as CBN Governor, names four deputies⁣

Cardoso assumes office as CBN confirms Emefiele’s resignation

by The Editor
September 22, 2023
0

...

Gov. Otti makes 14 new appointments

Gov. Otti makes 14 new appointments

by The Editor
September 20, 2023
0

...

Tinubu appoints Hakeem Baba-Ahmed as Special Adviser

Tinubu appoints Hakeem Baba-Ahmed as Special Adviser

by The Editor
September 18, 2023
0

...

ODDITIES

Varsity graduate attempts suicide over withheld results

Varsity graduate attempts suicide over withheld results

by The Editor
September 29, 2023
0

59-year-old man gets life imprisonment for raping two daughters

59-year-old man gets life imprisonment for raping two daughters

by The Editor
September 19, 2023
0

Guard allegedly impregnates three students in Anglican school

Guard allegedly impregnates three students in Anglican school

by The Editor
September 15, 2023
0

State of the States

Sanwo-Olu issues traders two days ultimatum to vacate red line rail tracks

Sanwo-Olu issues traders two days ultimatum to vacate red line rail tracks

by The Editor
September 28, 2023
0

...

Taraba approves N85,000 allowance for corps members

Taraba approves N85,000 allowance for corps members

by The Editor
September 26, 2023
0

...

2023 presidency: Ogun Governor dumps Tinubu for Osinbajo

Gov. Abiodun directs payment of N1bn gratuity to pensioners

by The Editor
September 20, 2023
0

...

Subsidy: Delta governor approves palliatives for students

Subsidy: Delta governor approves palliatives for students

by The Editor
September 20, 2023
0

...

  • Trending
  • Comments
  • Latest
UK licenses 266 Nigerian doctors in two months

UK licenses 266 Nigerian doctors in two months

August 3, 2022
US govt reaches agreement with Niger junta, resumes drone aircraft, crewed aircraft operations

US govt reaches agreement with Niger junta, resumes drone aircraft, crewed aircraft operations

September 16, 2023
Coup: Russia warns ECOWAS, others against Niger intervention threats

Coup: Russia warns ECOWAS, others against Niger intervention threats

August 2, 2023
Leah Sharibu married off to ISWAP Commander after ‘divorcing’ first husband – Report

Leah Sharibu married off to ISWAP Commander after ‘divorcing’ first husband – Report

September 28, 2023

Air Peace begins operations, offers airfare to Armed Forces personnel

170

Diezani breaks silence, reveals side of story in 3-part exclusive interview

26

FG’s N4trn contractual debts under Jonathan – National Mirror

21

2015: Washington Post condemns Jonathan for campaign slogan

20
Stay clear of workers’ pension fund – NLC warns Governors

Tinubu approves additional N10k for workers in bid to avert strike

October 2, 2023
Fed Govt declares May 1 as public holiday

Wages: All workers to benefit from N25,000 palliative, says Fed Govt

October 2, 2023
BUA slashes cement price to N3,500

BUA slashes cement price to N3,500

October 2, 2023
US court order on Tinubu’s Chicago Varsity academic records a national disgrace, says ex-minister

US court order on Tinubu’s Chicago Varsity academic records a national disgrace, says ex-minister

October 2, 2023

GLOBAL NEWS

Jehovah’s Witnesses spearhead global translation efforts

Jehovah’s Witnesses spearhead global translation efforts

by The Editor
September 30, 2023
0

...

Germany, Sweden, others deport 170 Nigerians in nine months – Report

Germany, Sweden, others deport 170 Nigerians in nine months – Report

by The Editor
September 30, 2023
0

...

Gunman kills 3 in twin Dutch shootings

Gunman kills 3 in twin Dutch shootings

by The Editor
September 29, 2023
0

...

Burkina Faso junta foils coup attempt

Burkina Faso junta foils coup attempt

by The Editor
September 28, 2023
0

...

Biden appoints two Nigerians, Imasogie, Ogwumike as advisers

Biden appoints two Nigerians, Imasogie, Ogwumike as advisers

by The Editor
September 28, 2023
0

...

EDITORIAL REVIEW

Tension in Benue, Adamawa over Ortom, Fintiri’s fate

Filling Supreme Court vacancies – Thisday

by The Editor
September 26, 2023
0

Inflation is deepening mass poverty – Punch

Inflation is deepening mass poverty – Punch

by The Editor
September 26, 2023
0

Teachers in private schools – Thisday

Teachers in private schools – Thisday

by The Editor
September 20, 2023
0

Reining-in boat mishaps in Nigeria – Vanguard

Reining-in boat mishaps in Nigeria – Vanguard

by The Editor
September 20, 2023
0

Rising cultism menace should be crushed – Punch

Rising cultism menace should be crushed – Punch

by The Editor
September 19, 2023
0

Opinion

Teacher’s Day Celebration: Tackling fundamentals of national educational system

Teacher’s Day Celebration: Tackling fundamentals of national educational system

by The Editor
September 27, 2023
0

...

Nigeria Immigration Service and hire purchase passports

Nigeria Immigration Service and hire purchase passports

by The Editor
September 5, 2023
0

...

Sudan crisis: Security threats and implications for Nigeria and beyond

Sudan crisis: Security threats and implications for Nigeria and beyond

by The Editor
August 30, 2023
0

...

Tinubu finds his own demons

Tinubu finds his own demons

by The Editor
August 3, 2023
0

...

  • UK licenses 266 Nigerian doctors in two months

    UK licenses 266 Nigerian doctors in two months

    130 shares
    Share 52 Tweet 33
  • US govt reaches agreement with Niger junta, resumes drone aircraft, crewed aircraft operations

    88 shares
    Share 35 Tweet 22
  • Coup: Russia warns ECOWAS, others against Niger intervention threats

    76 shares
    Share 30 Tweet 19
  • Leah Sharibu married off to ISWAP Commander after ‘divorcing’ first husband – Report

    71 shares
    Share 28 Tweet 18
  • NCC sets record clear in alleged leakage of Obi-Oyedepo call

    67 shares
    Share 27 Tweet 17
  • Home
  • Headlines
  • Latest News
  • Governance
  • Business
  • Financial Crimes
  • Opinion
  • Editorials

© 2022 TheCitizen Ng. All Rights Reserved.

No Result
View All Result
  • Home
  • Headlines
  • Latest News
  • Governance
  • Business
  • Financial Crimes
  • Opinion
  • Editorials

© 2022 TheCitizen Ng. All Rights Reserved.