Malware attack news and stories

Avast researchers have identified as many as 28 third-party extensions infected with malware for Google Chrome and Microsoft Edge.

The list includes 15 Google Chrome extensions and 13 extensions for Microsoft Edge. The report even highlights that more than 3 million users have installed these 28 malicious extensions.

All of these extensions exploit the name of popular platforms such as Instagram, Vimeo, Facebook, Spotify, SoundCloud, or even newspapers such as the New York Times to steal data from users and to direct them to dangerous phishing sites.

According to the report, a massive amount of data is stolen from users and incalculable the number of people damaged by phishing sites.

Avast researchers found Javascript code in the extensions that downloads malware onto the user’s PC. The malware also collects the time of the first access, the time of the last access, the name of the device, the operating system, the browser used, and its version.

Avast researchers are convinced that the ultimate goal of these extensions, which are all free, is to monetize the traffic itself by receiving a micro sum of money for each user sent to dangerous sites.

Here is the list of extensions for Chrome and Edge that are dangerous and must be removed immediately:

Google Chrome:

  • Direct Message for Instagram
  • DM for Instagram
  • Invisible mode for Instagram Direct Message
  • Downloader for Instagram
  • Phone app for Instagram
  • Stories for Instagram
  • Universal Video Downloader
  • Video Downloader for FaceBook ™
  • Vimeo ™ Video Downloader
  • Zoomer for Instagram and FaceBook
  • VK UnBlock. Works fast.
  • Odnoklassniki UnBlock. Works quickly.
  • Upload photo to Instagram ™
  • Spotify Music Downloader
  • The New York Times News

Microsoft Edge:

  • Direct Message for Instagram ™
  • Instagram Download Video & Image
  • Phone app for Instagram
  • Universal Video Downloader
  • Video Downloader for FaceBook ™
  • Vimeo ™ Video Downloader
  • Volume Controller
  • Stories for Instagram
  • Upload photo to Instagram ™
  • Pretty Kitty, The Cat Pet
  • Video Downloader for YouTube
  • SoundCloud Music Downloader
  • Instagram App with Direct Message DM

At the moment, all infected extensions are still available for download. Avast reported the findings to the Microsoft and Google Chrome teams. Both Microsoft and Google are currently investigating this issue. In the meantime, Avast recommends that users to disable or remove extensions for a while until the problem is resolved, and then scan the PC and remove malware if found.

2 COMMENTS

  1. Microsoft did auto disabled the Instagram App with Dm and gave a few notfications. One about Micorsoft to keep you safe, we ahve disabled it. This extenstoin contaions Virus. This is from a unknown source nad you may have not known it was installed. Since it was removed from the store, it is no more around.

  2. Hi. I was wondering if these malware were active on Chrome and Edge on Windows only, or also (for Chrome of course) on Linux and Mac computers?

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.