This Malware Installs Malicious Browser Extensions to Steal Users’ Passwords and Cryptos

Share:

A malicious extension for Chromium-based web browsers has been observed to be distributed via a long-standing Windows information stealer called ViperSoftX.

Czech-based cybersecurity company dubbed the rogue browser add-on VenomSoftX owing to its standalone features that enable it to access website visits, steal credentials and clipboard data, and even swap cryptocurrency addresses via an adversary-in-the-middle (AiTM) attack.

ViperSoftX, which first came to light in February 2020, was characterized by Fortinet as a JavaScript-based remote access trojan and cryptocurrency stealer. The malware’s use of a browser extension to advance its information-gathering goals was documented by Sophos threat analyst Colin Cowie earlier this year.

“This multi-stage stealer exhibits interesting hiding capabilities, concealed as small PowerShell scripts on a single line in the middle of otherwise innocent-looking large log files, among others,” Avast researcher Jan Rubín said in a technical write-up.

“ViperSoftX focuses on stealing cryptocurrencies, clipboard swapping, fingerprinting the infected machine, as well as downloading and executing arbitrary additional payloads, or executing commands.”

The distribution vector used to propagate ViperSoftX is typically done by means of cracked software for Adobe Illustrator and Microsoft Office that are hosted on file-sharing sites.

The downloaded executable file comes with a clean version of cracked software along with additional files that set up persistence on the host and harbor the ViperSoftX PowerShell script.

Bild13

Newer variants of the malware are also capable of loading the VenomSoftX add-on, which is retrieved from a remote server, to Chromium-based browsers such as Google Chrome, Microsoft Edge, Opera, Brave, and Vivaldi.

This is achieved by searching for LNK files for the browser applications and modifying the shortcuts with a “–load-extension” command line switch that points to the path where the unpacked extension is stored.

“The extension tries to disguise itself as well known and common browser extensions such as Google Sheets,” Rubín explained. “In reality, the VenomSoftX is yet another information stealer deployed onto the unsuspecting victim with full access permissions to every website the user visits from the infected browser.”

It’s worth noting that the –load-extension tactic has also been put to use by another browser-based information stealer referred to as ChromeLoader (aka Choziosi Loader or ChromeBack).

VenomSoftX, like ViperSoftX, is also orchestrated to steal cryptocurrencies from its victims. But unlike the latter, which functions as a clipper to reroute fund transfers to an attacker-controlled wallet, VenomSoftX tampers with API requests to crypto exchanges to drain the digital assets.

Services targeted by the extension include Blockchain.com, Binance, Coinbase, Gate.io, and Kucoin.

The development marks a new level of escalation to traditional clipboard swapping, while also not raising any immediate suspicion as the wallet address is replaced at a much more fundamental level.

Avast said it has detected and blocked over 93,000 infections since the start of 2022, with a majority of the impacted users located in India, the U.S., Italy, Brazil, the U.K., Canada, France, Pakistan, and South Africa.

An analysis of the hard-coded wallet addresses in the samples reveals that the operation has netted its authors a sum total of about $130,421 as of November 8, 2022, in various cryptocurrencies. The collective monetary gain has since dropped to $104,500.

“Since the transactions on blockchains/ledgers are inherently irreversible, when the user checks the transaction history of payments afterward, it is already too late,” Rubín said.

https://thehackernews.com/2022/11/this-malware-installs-malicious-browser.html

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:22 am, Jul 12, 2025
weather icon 20°C
L: 18° | H: 21°
clear sky
Humidity: 73 %
Pressure: 1018 mb
Wind: 5 mph ENE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 0%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:57 am
Sunset: 9:14 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
18° | 21°°C 0 mm 0% 10 mph 70 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
17° | 28°°C 0.51 mm 51% 6 mph 66 % 1014 mb 0 mm/h
Mon Jul 14 10:00 pm
weather icon
19° | 26°°C 0.3 mm 30% 15 mph 60 % 1015 mb 0 mm/h
Tue Jul 15 10:00 pm
weather icon
15° | 21°°C 0 mm 0% 12 mph 68 % 1018 mb 0 mm/h
Wed Jul 16 10:00 pm
weather icon
17° | 20°°C 1 mm 100% 13 mph 93 % 1017 mb 0 mm/h
Today 4:00 am
weather icon
17° | 19°°C 0 mm 0% 3 mph 70 % 1018 mb 0 mm/h
Today 7:00 am
weather icon
19° | 19°°C 0 mm 0% 4 mph 69 % 1018 mb 0 mm/h
Today 10:00 am
weather icon
26° | 26°°C 0 mm 0% 5 mph 46 % 1017 mb 0 mm/h
Today 1:00 pm
weather icon
29° | 29°°C 0 mm 0% 7 mph 32 % 1015 mb 0 mm/h
Today 4:00 pm
weather icon
30° | 30°°C 0 mm 0% 10 mph 29 % 1014 mb 0 mm/h
Today 7:00 pm
weather icon
25° | 25°°C 0 mm 0% 10 mph 37 % 1014 mb 0 mm/h
Today 10:00 pm
weather icon
21° | 21°°C 0 mm 0% 6 mph 46 % 1015 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 19°°C 0 mm 0% 4 mph 57 % 1014 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,615.36
1.74%
Ethereum(ETH)
€2,532.66
0.69%
XRP(XRP)
€2.34
8.23%
Tether(USDT)
€0.86
0.02%
Solana(SOL)
€139.73
-0.08%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.172305
4.24%
Shiba Inu(SHIB)
€0.000011
0.20%
Pepe(PEPE)
€0.000010
0.12%
Peanut the Squirrel(PNUT)
€0.246209
7.19%
Scroll to Top