Chrome and Edge users infected with malicious browser extensions that steal your personal data — what to do now (2024)

Chrome and Edge users infected with malicious browser extensions that steal your personal data — what to do now (1)

Hackers are using malicious browser extensions to infect both Google Chrome and Microsoft Edge with dangerous malware that can steal your personal data and leave your computer at risk of further attacks.

As reported by The Hacker News, this recently discovered malware campaign has been active since 2021 and so far, at least 300,000 Chrome and Edge users have fallen victim to it.

What makes this malware particularly dangerous is the fact that it can achieve persistence on infected PCs. This means that even if you delete the malicious extension, the malware will reactivate itself the next time you restart your computer.

Here’s everything you need to know about this malware campaign and how you can actually remove the malicious extension used in it once and for all.

Using malvertising to push fake sites

Chrome and Edge users infected with malicious browser extensions that steal your personal data — what to do now (2)

Like other malware campaigns, this one uses malvertising to trick unsuspecting users into downloading and installing risky software.

The hackers behind it have created lookalike sites that impersonate popular software and services like Roblox FPS Unlocker, YouTube, VLC media player, Steam or Keepass. While potential victims think they’re installing legitimate software or extensions, they’re actually downloading a trojan that installs the malicious extensions used by this malware.

The digitally signed malicious installers used in this campaign register a scheduled task on vulnerable PCs that then executes a PowerShell script which downloads and executes the next-stage payload from a hacker-controlled remote server.

Sign up to get the BEST of Tom's Guide direct to your inbox.

Get instant access to breaking news, the hottest reviews, great deals and helpful tips.

As part of this next-stage payload, the malware modifies an infected PCs Windows Registry to force the installation of Chrome and Edge extensions which are used for ad fraud by hijacking web searches on Google and Bing and then redirecting them through the hackers’ servers. To make matters worse, newer versions of this malware can even prevent browser updates from being installed, putting victims at risk of other attacks.

Fortunately, there is a fix but it does take some technical know how.

How to remove this malware from your PC for good

Chrome and Edge users infected with malicious browser extensions that steal your personal data — what to do now (3)

In a blog post detailing the findings of its security researchers, ReasonLabs provides further insight on how to properly remove this malware and the malicious extensions used in this campaign from your PC.

First things first, you need to remove the scheduled task from your PC. This is done by clicking on the Start Menu or pressing the Windows key on your keyboard and then searching for Task Scheduler.

Once Task Scheduler is opened, you need to click on the Task Scheduler Library to show all of the tasks on your PC. While the task name used by this malware varies, you can identify it by clicking on tasks, opening them and then clicking on Actions. In the table below Actions, you can look at their Details and here, you want to look for a path to “c:\windows\system32” and a PowerShell script or a file ending with “.ps1”. ReasonLabs notes that the task name will often be similar to the PowerShell script name. Once you’ve found the malicious task, right click on its name and then click Delete.

After this, you then need to remove the registry keys that are forcing the malicious extensions in your browser. This is more difficult but you can open the Registry Editor the same way that you did with the Task Scheduler. Keep in mind though that you shouldn’t mess with your computer’s registry unless you absolutely know what you’re doing. When in doubt, ask a friend for help or take your PC to a professional.

With the Registry Editor opened, you need to go to “Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist”. In the right pane here, there will be a list of extensions with a numerical value as “Name” and Extension ID as “Data”. Then right click on the name and then click Delete. You also have to do this for this registry key as well: Computer\HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Policies\Google\Chrome\ExtensionInstallForcelist.”

As this malware affects both Chrome and Edge, you will need to repeat the same process for the Edge extensions at this path: “Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallForcelist”.

While you could delete the malware files yourself, you’re much better off using one of the best antivirus software solutions to do it for you. If you do want to do so manually, you can find instructions at the end of ReasonLabs’ blog post linked above.

Going through the process of removing these malicious extensions and the malware they’ve dropped on your PC will likely be more than enough to ensure you think twice before downloading new software or browser extensions from untrustworthy sources. If you do want to download a new extension, do so from the Chrome Web Store or from the Microsoft Edge Add-on Store instead.

More from Tom's Guide

  • Made by Google event live blog — Pixel 9, Pixel 9 Pro Fold and Pixel Watch 3 news
  • 2.9 billion hit in one of the largest data breaches ever
  • Google just fixed 46 security flaws, including an actively exploited zero-day
Chrome and Edge users infected with malicious browser extensions that steal your personal data — what to do now (11)

Anthony Spadafora

Senior Editor Security and Networking

Anthony Spadafora is the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to password managers and the best way to cover your whole home or business with Wi-Fi. Before joining the team, he wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home.

More about malware and adware

Dangerous new Android malware drains your bank accounts and completely wipes your device — how to stay safeThis dangerous Android spyware has returned via malicious Play Store apps — delete them right now

Latest

NYT Connections today hints and answers — Wednesday, August 15 (#431)
See more latest►

2 CommentsComment from the forums

  • steve907

    What about Chrome and Edge on MacOS? What's the exposure there?

    Reply

  • Anthony Spadafora

    steve907 said:

    What about Chrome and Edge on MacOS? What's the exposure there?

    So this malware only affects PCs due to how it uses Scheduled Tasks and tweaks to the Windows Registry to establish persistence on an infected computer. You should be fine using either Chrome or Edge on Mac. Just think of this piece as a good reminder to always be careful when looking for new software online or installing new extensions for your browser.

    Reply

Most Popular
Robots are about to have an 'iPhone moment' — and its all thanks to AI
The new Dell XPS 13 is 24% off — and it has the longest battery life we’ve ever tested
How to watch 'Rick and Morty: The Anime' online and from anywhere — release date, TV channels
Google Pixel 8 Pro just got a feature that was announced last October — just in time for Pixel 9 launch
Prime Video top 10 movies — here’s the 3 worth watching right now
'It Ends With Us' streaming date: when will it be available to watch?
Netflix's dark sci-fi show with 100% on Rotten Tomatoes gets renewed for season 2
Google may have to give up Chrome, Android and AI data because of monopoly ruling
Pixel 9 phones won’t be released running Android 15 — what the heck is happening?
Apple TV Plus just landed a new comedy-drama show — and it's 92% on Rotten Tomatoes
Elon Musk drops Grok 2 — the X-based AI chatbot is now more powerful and can make images
Chrome and Edge users infected with malicious browser extensions that steal your personal data — what to do now (2024)
Top Articles
Find a 24-Hour Pharmacy Near Me Open Now | Bucks & Cents
9289 Crystal Springs Drive Drive, Conroe, TX 77303 - MLS #67193042 - 3 beds, 3 baths
Edina Omni Portal
Camera instructions (NEW)
Cintas Pay Bill
Walgreens Pharmqcy
Research Tome Neltharus
Phcs Medishare Provider Portal
Amtrust Bank Cd Rates
Here are all the MTV VMA winners, even the awards they announced during the ads
Southside Grill Schuylkill Haven Pa
His Lost Lycan Luna Chapter 5
Www Craigslist Louisville
Umn Pay Calendar
Legacy First National Bank
Indiana Immediate Care.webpay.md
General Info for Parents
Oc Craiglsit
Directions To O'reilly's Near Me
Tcgplayer Store
The ULTIMATE 2023 Sedona Vortex Guide
Highland Park, Los Angeles, Neighborhood Guide
Hanger Clinic/Billpay
Gentle Dental Northpointe
Amih Stocktwits
Jackie Knust Wendel
Bra Size Calculator & Conversion Chart: Measure Bust & Convert Sizes
CVS Health’s MinuteClinic Introduces New Virtual Care Offering
Uky Linkblue Login
Smayperu
Wake County Court Records | NorthCarolinaCourtRecords.us
Bee And Willow Bar Cart
Mp4Mania.net1
Frank 26 Forum
Dynavax Technologies Corp (DVAX)
D-Day: Learn about the D-Day Invasion
T&Cs | Hollywood Bowl
Keir Starmer looks to Italy on how to stop migrant boats
Gopher Hockey Forum
Lucyave Boutique Reviews
Streameast Io Soccer
How the Color Pink Influences Mood and Emotions: A Psychological Perspective
Smoke From Street Outlaws Net Worth
Blog Pch
The Plug Las Vegas Dispensary
Greg Steube Height
Game Like Tales Of Androgyny
Sml Wikia
Glowforge Forum
Taterz Salad
Arre St Wv Srj
Fetllife Com
Latest Posts
Article information

Author: Rob Wisoky

Last Updated:

Views: 6426

Rating: 4.8 / 5 (48 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Rob Wisoky

Birthday: 1994-09-30

Address: 5789 Michel Vista, West Domenic, OR 80464-9452

Phone: +97313824072371

Job: Education Orchestrator

Hobby: Lockpicking, Crocheting, Baton twirling, Video gaming, Jogging, Whittling, Model building

Introduction: My name is Rob Wisoky, I am a smiling, helpful, encouraging, zealous, energetic, faithful, fantastic person who loves writing and wants to share my knowledge and understanding with you.