Concise Cyber

Subscribe below for free to get these delivered straight to your inbox

Advertisements
Cybercriminals Exploit Browser Push Notifications to Deliver FAKEUPDATES Malware
Advertisements

Security researchers from Malwarebytes have identified an ongoing malvertising campaign that leverages browser push notifications to distribute malware. The campaign employs social engineering tactics to trick users into downloading and executing the payload known as FAKEUPDATES or SocGholish.

Attack Vector: Malvertising and Notification Hijacking

The attack begins when users visit websites, primarily adult-themed sites, that contain malicious advertisements. These ads redirect the user to a page designed to deceive them into accepting push notifications. The fraudulent page often impersonates a CAPTCHA check or an age verification gate, displaying messages such as “Click Allow to confirm you are not a robot.”

When a user clicks the “Allow” button, they inadvertently subscribe their browser to a push notification service controlled by the cybercriminals. This technique exploits a legitimate browser feature, allowing it to bypass many traditional ad-blocking tools.

Malware Delivery Through Deceptive Updates

After the subscription is established, the attackers send deceptive push notifications to the user’s browser. These notifications are crafted to look like legitimate software update alerts, often using the logo of the user’s browser, such as Google Chrome, with text prompting them to install a critical update.

Clicking the notification initiates the download of a malicious JavaScript file, frequently named Update.js. If the user executes this file, it installs the FAKEUPDATES malware, also known as SocGholish. This specific malware has been associated with various threat actors, including the group behind the Clop ransomware (TA505) and the Russian cyber-criminal group Evil Corp.

All articles are written here with the help of AI on the basis of openly available information which cannot be independently verified. We do strive to quote the relevant sources.The intent is only to summarise what is already reported in public forum in our own wordswith no intention to plagarise or copy other person’s work.The publisher has no intent to defame or cause offence to anyone, any person or any organisation at any moment.The publisher assumes no responsibility for any damage or loss caused by making decisions on the basis of whatever is published on cyberconcise.com.You’re advised to do your own checks and balances before making any decision, and owners and publishers at cyberconcise.com cannot be held accountable for its resulting ramifications.If you have any objections, concerns or point out anything factually incorrect, please reach out using the form on https://concisecyber.com/about/

Discover more from Concise Cyber

Subscribe now to keep reading and get access to the full archive.

Continue reading