Chrome and Edge users infected with malicious browser extensions that steal your personal data — what to do now (2024)

Chrome and Edge users infected with malicious browser extensions that steal your personal data — what to do now (1)

Hackers are using malicious browser extensions to infect both Google Chrome and Microsoft Edge with dangerous malware that can steal your personal data and leave your computer at risk of further attacks.

As reported by The Hacker News, this recently discovered malware campaign has been active since 2021 and so far, at least 300,000 Chrome and Edge users have fallen victim to it.

What makes this malware particularly dangerous is the fact that it can achieve persistence on infected PCs. This means that even if you delete the malicious extension, the malware will reactivate itself the next time you restart your computer.

Here’s everything you need to know about this malware campaign and how you can actually remove the malicious extension used in it once and for all.

Using malvertising to push fake sites

Chrome and Edge users infected with malicious browser extensions that steal your personal data — what to do now (2)

Like other malware campaigns, this one uses malvertising to trick unsuspecting users into downloading and installing risky software.

The hackers behind it have created lookalike sites that impersonate popular software and services like Roblox FPS Unlocker, YouTube, VLC media player, Steam or Keepass. While potential victims think they’re installing legitimate software or extensions, they’re actually downloading a trojan that installs the malicious extensions used by this malware.

The digitally signed malicious installers used in this campaign register a scheduled task on vulnerable PCs that then executes a PowerShell script which downloads and executes the next-stage payload from a hacker-controlled remote server.

Sign up to get the BEST of Tom's Guide direct to your inbox.

Get instant access to breaking news, the hottest reviews, great deals and helpful tips.

As part of this next-stage payload, the malware modifies an infected PCs Windows Registry to force the installation of Chrome and Edge extensions which are used for ad fraud by hijacking web searches on Google and Bing and then redirecting them through the hackers’ servers. To make matters worse, newer versions of this malware can even prevent browser updates from being installed, putting victims at risk of other attacks.

Fortunately, there is a fix but it does take some technical know how.

How to remove this malware from your PC for good

Chrome and Edge users infected with malicious browser extensions that steal your personal data — what to do now (3)

In a blog post detailing the findings of its security researchers, ReasonLabs provides further insight on how to properly remove this malware and the malicious extensions used in this campaign from your PC.

First things first, you need to remove the scheduled task from your PC. This is done by clicking on the Start Menu or pressing the Windows key on your keyboard and then searching for Task Scheduler.

Once Task Scheduler is opened, you need to click on the Task Scheduler Library to show all of the tasks on your PC. While the task name used by this malware varies, you can identify it by clicking on tasks, opening them and then clicking on Actions. In the table below Actions, you can look at their Details and here, you want to look for a path to “c:\windows\system32” and a PowerShell script or a file ending with “.ps1”. ReasonLabs notes that the task name will often be similar to the PowerShell script name. Once you’ve found the malicious task, right click on its name and then click Delete.

After this, you then need to remove the registry keys that are forcing the malicious extensions in your browser. This is more difficult but you can open the Registry Editor the same way that you did with the Task Scheduler. Keep in mind though that you shouldn’t mess with your computer’s registry unless you absolutely know what you’re doing. When in doubt, ask a friend for help or take your PC to a professional.

With the Registry Editor opened, you need to go to “Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist”. In the right pane here, there will be a list of extensions with a numerical value as “Name” and Extension ID as “Data”. Then right click on the name and then click Delete. You also have to do this for this registry key as well: Computer\HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Policies\Google\Chrome\ExtensionInstallForcelist.”

As this malware affects both Chrome and Edge, you will need to repeat the same process for the Edge extensions at this path: “Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallForcelist”.

While you could delete the malware files yourself, you’re much better off using one of the best antivirus software solutions to do it for you. If you do want to do so manually, you can find instructions at the end of ReasonLabs’ blog post linked above.

Going through the process of removing these malicious extensions and the malware they’ve dropped on your PC will likely be more than enough to ensure you think twice before downloading new software or browser extensions from untrustworthy sources. If you do want to download a new extension, do so from the Chrome Web Store or from the Microsoft Edge Add-on Store instead.

More from Tom's Guide

  • Made by Google event live blog — Pixel 9, Pixel 9 Pro Fold and Pixel Watch 3 news
  • 2.9 billion hit in one of the largest data breaches ever
  • Google just fixed 46 security flaws, including an actively exploited zero-day
Chrome and Edge users infected with malicious browser extensions that steal your personal data — what to do now (11)

Anthony Spadafora

Senior Editor Security and Networking

Anthony Spadafora is the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to password managers and the best way to cover your whole home or business with Wi-Fi. Before joining the team, he wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home.

More about malware and adware

Dangerous new Android malware drains your bank accounts and completely wipes your device — how to stay safeThis dangerous Android spyware has returned via malicious Play Store apps — delete them right now

Latest

Leicester vs Tottenham live stream: How to watch Premier League game online
See more latest►

2 CommentsComment from the forums

  • steve907

    What about Chrome and Edge on MacOS? What's the exposure there?

    Reply

  • Anthony Spadafora

    steve907 said:

    What about Chrome and Edge on MacOS? What's the exposure there?

    So this malware only affects PCs due to how it uses Scheduled Tasks and tweaks to the Windows Registry to establish persistence on an infected computer. You should be fine using either Chrome or Edge on Mac. Just think of this piece as a good reminder to always be careful when looking for new software online or installing new extensions for your browser.

    Reply

Most Popular
7 best video game adaptations to stream right now
NYT Connections today hints and answers — Sunday, August 18 (#434)
NYT Strands today — hints, spangram and answers for game #168 (Sunday, August 18 2024)
Chelsea vs Man City live stream: How to watch Premier League game online and on TV, team news
UFC 305 live stream: How to watch du Plessis vs Adesanya online from anywhere today, match card, start time
Brentford vs Crystal Palace live stream: How to watch Premier League game online and on TV, team news
Netflix top 10 movies — here's the 3 worth watching right now
Google responds to #TeamPixel controversy that would ‘cease relationship’ with creators that preferred other devices
Latest iPhones could one day be demoed on Vision Pro
These House of Representatives members are at the highest risk of being exposed online
Hedra lets you give AI characters a voice — this new model is a huge step up
Chrome and Edge users infected with malicious browser extensions that steal your personal data — what to do now (2024)

References

Top Articles
Exact Sciences Announces Second-Quarter 2024 Results
New External Design Temperatures and Geospatial Models for Poland and Central Europe for Building Heat Load Calculations
San Angelo, Texas: eine Oase für Kunstliebhaber
Golden Abyss - Chapter 5 - Lunar_Angel
Parke County Chatter
Best Team In 2K23 Myteam
What Are the Best Cal State Schools? | BestColleges
Fort Carson Cif Phone Number
Green Bay Press Gazette Obituary
Palace Pizza Joplin
Mikayla Campino Video Twitter: Unveiling the Viral Sensation and Its Impact on Social Media
Publix 147 Coral Way
My Vidant Chart
Edgar And Herschel Trivia Questions
Uc Santa Cruz Events
Animal Eye Clinic Huntersville Nc
U/Apprenhensive_You8924
Convert 2024.33 Usd
Itziar Atienza Bikini
Richland Ecampus
Isaidup
Yisd Home Access Center
Craigslist Alo
Harbor Freight Tax Exempt Portal
Dal Tadka Recipe - Punjabi Dhaba Style
Vivification Harry Potter
Taylored Services Hardeeville Sc
Amazing Lash Bay Colony
Isablove
Street Fighter 6 Nexus
Rlcraft Toolbelt
Autotrader Bmw X5
Kvoa Tv Schedule
Foolproof Module 6 Test Answers
Manatee County Recorder Of Deeds
Myanswers Com Abc Resources
Publictributes
Mixer grinder buying guide: Everything you need to know before choosing between a traditional and bullet mixer grinder
Joey Gentile Lpsg
11301 Lakeline Blvd Parkline Plaza Ctr Ste 150
Jack In The Box Menu 2022
Achieving and Maintaining 10% Body Fat
Pa Legion Baseball
Hanco*ck County Ms Busted Newspaper
Top 1,000 Girl Names for Your Baby Girl in 2024 | Pampers
Lyons Hr Prism Login
Zipformsonline Plus Login
Joy Taylor Nip Slip
Mlb Hitting Streak Record Holder Crossword Clue
A Snowy Day In Oakland Showtimes Near Maya Pittsburg Cinemas
Adams County 911 Live Incident
Invitation Quinceanera Espanol
Latest Posts
Article information

Author: Greg O'Connell

Last Updated:

Views: 5763

Rating: 4.1 / 5 (62 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Greg O'Connell

Birthday: 1992-01-10

Address: Suite 517 2436 Jefferey Pass, Shanitaside, UT 27519

Phone: +2614651609714

Job: Education Developer

Hobby: Cooking, Gambling, Pottery, Shooting, Baseball, Singing, Snowboarding

Introduction: My name is Greg O'Connell, I am a delightful, colorful, talented, kind, lively, modern, tender person who loves writing and wants to share my knowledge and understanding with you.