< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Chromium browsers targeted by fake update malware

A malware campaign is targeting users of Chromium-based browsers, including Google Chrome, Brave, and Opera, by using deceptive pop-up notifications that mimic critical browser updates. These fake alerts use alarmist language, claiming that an update is required to prevent the browser from malfunctioning.

When users click the fraudulent update button, the system downloads an executable file with a .exe or .vbs extension from an external source. If executed, the malware can hijack the computer's processing power to mine cryptocurrency without the user's consent. Common symptoms of infection include decreased system performance, increased energy consumption, and constant fan activity.

Security reports suggest that a specific browser extension, ‘Enable Right Click & Copy Smart Unlock + OCR’, may be acting as an intermediary for these malicious pop-ups, though it is unclear if the original developers are responsible or if the tool has been compromised. While Windows Defender has successfully blocked some downloads, some antivirus tools, such as Malwarebytes, have reportedly failed to detect the threat. Legitimate browser updates are managed internally through the browser settings and never via external pop-up downloads.

Entities

Brave · Google Chrome · Malwarebytes · Opera · Windows Defender