🛡️ State Resident Data Privacy Rights: Generate Your Statutory Deletion Notice → Get Legal Kit ($5) →
SolidTechNewsGet Legal Kit ($5)
security-privacy •

Google Chrome End Users Focused with 'missing Font' Malware Scam

By Enterprise Infrastructure Desk
5 min read
Protect Your Consumer Data: Citing federal FCRA & state privacy laws allows you to demand statutory removal of your records.
Generate Dispute ($5)

Security researcher Mahmoud Al-Qudsi spotted a “drive-by-infection” hack on a compromised WordPress internet site in which the scam was working with JavaScript to change how text was displayed on the internet site, then urging end users to download a deal with for the issue. Al-Qudsi explained, “This attack gets a whole lot of items appropriate that a lot of other individuals fail at. The premise is basically plausible: the text won’t render, and it claims that is brought about by a missing font, which it then prompts you to download and put in.” Screenshots present a warning box created by the hacker that seems authentic. A message exhibit claims: “The web page you are seeking to load is displayed improperly as it uses the ‘Hoefler Text’ font. To deal with the mistake and exhibit the text, you have to update the ‘Chrome Font Pack’.” By clicking on the “Update” button, which sports the suitable colour blue that Chrome uses, a file termed “Chrome Font v7.five.one.exe” downloads and the webpage morphs to “helpfully” push the person to run the virus. This file is not recognised by possibly Windows Defender or Chrome as staying a virus. Only 9 out of 59 antivirus scanners identify it as hazardous. If infected, VirusTotal revealed the malware will snoop on files and files and can be utilized to inspect main Windows process files. Whilst Chrome won’t peg the file as staying destructive, it is blocked by a warning that claims “this file isn’t downloaded quite often”. Tod Beardsley, investigation director at Rapid7 commented: “So far, the assaults seem to be limited to compromised WordPress websites – a industry that is, regretably, wealthy with targets.” “Chrome end users really should be knowledgeable that authentic warnings from the Chrome browser will never seem as overlays to a web page. Specifically, Chrome does not give any functionality for prompting for a missing font download, and all these types of prompts are sourced from malware or malvertising strategies. In the exceptional situations the browser desires to talk a safety or misconfiguration warning to the person, these warnings will seem as a comprehensive, substitution page, these types of as the familiar ‘Your relationship is not private’ warning for misconfigured SSL certificates.” This article originally appeared at scmagazineuk.com

Source url Share this:Click to share on Twitter (Opens in new window)Click to share on Facebook (Opens in new window)Click to share on Google+ (Opens in new window)

Related

Security researcher Mahmoud Al-Qudsi spotted a “drive-by-infection” hack on a compromised WordPress internet site in which the scam was working with JavaScript to change how text was displayed on the internet site, then urging end users to download a deal with for the issue.

Al-Qudsi explained, “This attack gets a whole lot of items appropriate that a lot of other individuals fail at. The premise is basically plausible: the text won’t render, and it claims that is brought about by a missing font, which it then prompts you to download and put in.”

Screenshots present a warning box created by the hacker that seems authentic. A message exhibit claims: “The web page you are seeking to load is displayed improperly as it uses the ‘Hoefler Text’ font. To deal with the mistake and exhibit the text, you have to update the ‘Chrome Font Pack’.”

By clicking on the “Update” button, which sports the suitable colour blue that Chrome uses, a file termed “Chrome Font v7.five.one.exe” downloads and the webpage morphs to “helpfully” push the person to run the virus.

This file is not recognised by possibly Windows Defender or Chrome as staying a virus. Only 9 out of 59 antivirus scanners identify it as hazardous. If infected, VirusTotal revealed the malware will snoop on files and files and can be utilized to inspect main Windows process files.

Whilst Chrome won’t peg the file as staying destructive, it is blocked by a warning that claims “this file isn’t downloaded quite often”.

Tod Beardsley, investigation director at Rapid7 commented: “So far, the assaults seem to be limited to compromised WordPress websites – a industry that is, regretably, wealthy with targets.”

“Chrome end users really should be knowledgeable that authentic warnings from the Chrome browser will never seem as overlays to a web page. Specifically, Chrome does not give any functionality for prompting for a missing font download, and all these types of prompts are sourced from malware or malvertising strategies. In the exceptional situations the browser desires to talk a safety or misconfiguration warning to the person, these warnings will seem as a comprehensive, substitution page, these types of as the familiar ‘Your relationship is not private’ warning for misconfigured SSL certificates.”

This article originally appeared at scmagazineuk.com

Post Share Instagram

Facing Data Privacy or Credit Dispute Issues?

Generate certified statutory opt-out and dispute legal notices tailored to your state regulations in 60 seconds.

Access Legal Vault ($5)