Kaspersky Lab cautions about malware-laden Chrome extensions, that are being uploaded and hosted on Google’s Chrome Web Store.
The malware in question is pretends to be a Flash Player installer but instead downloads a Trojan. Once installed, it takes control of a user’s Facebook profile and starts posting messages encouraging the victim’s friends to install the same extension. It also starts to automatically Like certain pages.
This, according to Fabio Assolini, is part of a pay-per-Like scheme that helps the attackers to cash in.
The attacks starts off as suggestions to download Facebook apps. The suggestions comes with messages saying your friends have also downloaded the same app.
This extension and its variants were found to be largely confined to Brazil and other Portuguese-speaking nations.
This trick is neither new nor specific to Chrome browser. However, it is easier for users to fall for it since the extension is distributed from trusted place like the official Chrome Web store.
The extension was notified to Google and was duly removed. But, new variations of the extensions are being reportedly uploaded by the scammers on a regular basis.
So, users will have to use their best judgement and stay informed in order to stay safe from the millions of scams on the Internet that are doing the rounds.
Remember this for future reference. Adobe Flash Player is a plug-in and not an extension, and it is installed outside the browser.
{ 0 comments }