Be on the lookout for this malware that hijacks your browser and generates bogus search results

Popup link.
(Image credit: Getty images)

Researchers at RedCanary (thanks, bleepingcomputer) have noticed an uptick in ChromeLoader activity since the beginning of the year. This malware can completely take over your browser, manipulating search results in an effort to get you to click into a network of shady malicious sites and potentially steal your user data. 

This nasty bit of malware is what is called a browser hijacker. It changes a user's browser settings to display search results and ads for bogus sites, surveys, and even adult games on both Windows PCs and macOS systems. Despite being called ChromeLoader, it does affect Apple Safari in addition to Google Chrome. 

According to RedCanary's research, the way ChromeLoader infiltrates most systems is by way of a malicious ISO archive file disguised as a cracked executable for a computer game or commercial software and distributed through torrent sites. Additionally, QR codes inside of Twitter posts promoting cracked Android games have also been found to contain links to ChromeLoader distributing sites.

In most cases, after being infected with a browser hijacker the user is redirected to a series of bad sites that are usually part of an affiliate network. Each visit to these sites funnels revenue to the malware's creator. ChromeLoader does that and more. 

RedCanary says that "ChromeLoader uses PowerShell to inject itself into the browser and add a malicious extension to it, a technique we don’t see very often (and one that often goes undetected by other security tools)."

RedCanary goes on to outline a worst case scenario for this kind of malware: "If applied to a higher-impact threat—such as a credential harvester or spyware—this PowerShell behavior could help malware gain an initial foothold and go undetected before performing more overtly malicious activity, like exfiltrating data from a user’s browser sessions." 

On Macs, ChromeLoader has a similar MO where once you double-click on the DMG file, its installer script takes over and the bad browser extension starts to do its thing. 

The best advice we can give is that if you frequent torrent sites, exercise an extra layer of caution when clicking on any links, and don't open any executable files you don't recognize. And if you see an advertisement for a cracked version of Cyberpunk 2070, just don't click on it. 

Windows 11 reviewHow to install Windows 11What you need to know before upgradingWindows 11 TPM requirements

Windows 11 review: What we think of the new OS
How to install Windows 11: Safe and secure install
What you need to know before upgrading: Things to note before downloading the latest OS
Windows 11 TPM requirements: Microsoft's strict security policy explained

Jorge Jimenez
Hardware writer, Human Pop-Tart

Jorge is a hardware writer from the enchanted lands of New Jersey. When he's not filling the office with the smell of Pop-Tarts, he's reviewing all sorts of gaming hardware, from laptops with the latest mobile GPUs to gaming chairs with built-in back massagers. He's been covering games and tech for over ten years and has written for Dualshockers, WCCFtech, Tom's Guide, and a bunch of other places on the world wide web. 

Read more
Steam logo
A web3 free-to-play survival game found to be a front for installing malware on your PC has finally been removed from Steam
Team Fortress Spy being shocked
An FPS studio pulled its game from Steam after it got caught linking to malware disguised as a demo, but the dev insists it was actually the victim of a labyrinthine conspiracy
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
Three Magikarp Pokémon
The FBI used self-destruct on malware infecting over 4,000 US computers, it's super effective
Edge
Somehow, some way, Edge has over 30% market share in the US on Windows—and has taken share for over 3 years
ANKARA, TURKIYE - SEPTEMBER 06: In this photo illustration, Chrome logo is being displayed on a mobile phone screen in front of computer screen in Ankara, Turkiye on September 06, 2023.
uBlock and a handful of other popular Google Chrome extensions have been axed overnight, but some of them just require turning off and on again
Latest in Hardware
Logitech G PowerPlay charging station mouse pad
Logitech G PowerPlay 2 mouse pad review
Nvidia headquarters
Nvidia CEO sets sights on making 'several hundred billion' dollars worth of electronics in the USA over the next four years, increasing the chance of your next GPU being made in America
The Asus ROG Astral GeForce RTX 5090 Dhahab Edition, a gold-plated graphics card on a sand dune background
A Jensen Huang-signed version of this golden Asus RTX 5090 will be auctioned off to support relief efforts for the California wildfires
Corsair TC100 Relaxed gaming chair
Are you sitting down? My favourite budget gaming chair is the cheapest it’s ever been at only $170
An MSI Vanguard RTX 5080 launch edition next to a Dragon Lucky figurine
You can win an MSI RTX 5080 in Taiwan if you collect nine dragon figurines given away with *checks notes* MSI RTX 50-series GPUs
Screenshots from Half-Life 2 RTX, showing the various new effects delivered by full ray tracing and enhanced assets.
Microsoft announces DirectX Raytracing 1.2 claiming 'game changing' performance benefits but it looks like the important stuff is already in Nvidia's RTX GPUs, even the old ones
Latest in News
A shirtless man rides a big fish underwater
Ark devs distance themselves from AI-generated trailer: 'we did not know that they were doing it'
Team Fortress Spy being shocked
An FPS studio pulled its game from Steam after it got caught linking to malware disguised as a demo, but the dev insists it was actually the victim of a labyrinthine conspiracy
Neighbors Suburban Warfare screenshot a child aims a slingshot at a man from across a cul-de-sac.
A beta of backyard FPS Neighbors: Suburban Warfare is out now, and the balance discussion is hysterical: nerf trash can lids and children
Grand Theft Auto 6 trailer still - woman in the front seat of a car, looking out the back window while holding a wad of cash
The specter of a GTA 6 delay haunts the games industry: 'Some companies are going to tank' if they guess wrong, says analyst
Screenshot from Wreckfest 2
Wreckfest 2 has hit early access for your car-obliterating combat racing enjoyment
Alma, the handler from Monster Hunter Wilds, closes her eyes and looks a little disappointed.
Monster Hunter director joined an online hunt, carted first: 'I feel bad about that'