🛡️ State Resident Data Privacy Rights: Generate Your Statutory Deletion Notice → Get Legal Kit ($5) →
SolidTechNewsGet Legal Kit ($5)
security-privacy •

Google Chrome Buyers Targeted with 'missing Font' Malware Scam

By Enterprise Infrastructure Desk
5 min read
Protect Your Consumer Data: Citing federal FCRA & state privacy laws allows you to demand statutory removal of your records.
Generate Dispute ($5)

Safety researcher Mahmoud Al-Qudsi noticed a “drive-by-infection” hack on a compromised WordPress web page in which the scam was using JavaScript to adjust how textual content was exhibited on the web page, then urging buyers to obtain a resolve for the issue. Al-Qudsi reported, “This attack gets a whole lot of points suitable that lots of some others fail at. The premise is essentially plausible: the textual content won’t render, and it says that is brought about by a lacking font, which it then prompts you to obtain and put in.” Screenshots clearly show a warning box developed by the hacker that seems genuine. A concept show says: “The internet website page you are seeking to load is exhibited improperly as it utilizes the ‘Hoefler Text’ font. To resolve the error and show the textual content, you have to update the ‘Chrome Font Pack’.” By clicking on the “Update” button, which sporting activities the correct colour blue that Chrome utilizes, a file called “Chrome Font v7.5.1.exe” downloads and the webpage morphs to “helpfully” drive the person to operate the virus. This file is not recognised by either Windows Defender or Chrome as remaining a virus. Only 9 out of 59 antivirus scanners identify it as risky. If contaminated, VirusTotal unveiled the malware will snoop on files and documents and can be applied to examine main Windows technique files. Whilst Chrome won’t peg the file as remaining destructive, it is blocked by a warning that says “this file isn’t really downloaded pretty often”. Tod Beardsley, analysis director at Rapid7 commented: “So significantly, the assaults surface to be minimal to compromised WordPress internet sites – a area that is, regretably, loaded with targets.” “Chrome buyers should really be conscious that genuine warnings from the Chrome browser will never ever surface as overlays to a internet website page. Specifically, Chrome does not offer you any performance for prompting for a lacking font obtain, and all such prompts are sourced from malware or malvertising campaigns. In the unusual conditions the browser wants to communicate a protection or misconfiguration warning to the person, these warnings will surface as a full, substitute website page, such as the familiar ‘Your link is not private’ warning for misconfigured SSL certificates.” This write-up originally appeared at scmagazineuk.com

Supply url Share this:Click to share on Twitter (Opens in new window)Click to share on Facebook (Opens in new window)Click to share on Google+ (Opens in new window)

Related

Safety researcher Mahmoud Al-Qudsi noticed a “drive-by-infection” hack on a compromised WordPress web page in which the scam was using JavaScript to adjust how textual content was exhibited on the web page, then urging buyers to obtain a resolve for the issue.

Al-Qudsi reported, “This attack gets a whole lot of points suitable that lots of some others fail at. The premise is essentially plausible: the textual content won’t render, and it says that is brought about by a lacking font, which it then prompts you to obtain and put in.”

Screenshots clearly show a warning box developed by the hacker that seems genuine. A concept show says: “The internet website page you are seeking to load is exhibited improperly as it utilizes the ‘Hoefler Text’ font. To resolve the error and show the textual content, you have to update the ‘Chrome Font Pack’.”

By clicking on the “Update” button, which sporting activities the correct colour blue that Chrome utilizes, a file called “Chrome Font v7.5.1.exe” downloads and the webpage morphs to “helpfully” drive the person to operate the virus.

This file is not recognised by either Windows Defender or Chrome as remaining a virus. Only 9 out of 59 antivirus scanners identify it as risky. If contaminated, VirusTotal unveiled the malware will snoop on files and documents and can be applied to examine main Windows technique files.

Whilst Chrome won’t peg the file as remaining destructive, it is blocked by a warning that says “this file isn’t really downloaded pretty often”.

Tod Beardsley, analysis director at Rapid7 commented: “So significantly, the assaults surface to be minimal to compromised WordPress internet sites – a area that is, regretably, loaded with targets.”

“Chrome buyers should really be conscious that genuine warnings from the Chrome browser will never ever surface as overlays to a internet website page. Specifically, Chrome does not offer you any performance for prompting for a lacking font obtain, and all such prompts are sourced from malware or malvertising campaigns. In the unusual conditions the browser wants to communicate a protection or misconfiguration warning to the person, these warnings will surface as a full, substitute website page, such as the familiar ‘Your link is not private’ warning for misconfigured SSL certificates.”

This write-up originally appeared at scmagazineuk.com

Post Share Instagram

Facing Data Privacy or Credit Dispute Issues?

Generate certified statutory opt-out and dispute legal notices tailored to your state regulations in 60 seconds.

Access Legal Vault ($5)