Researchers from ReasonLabs uncovered a large-scale malware campaign targeting users through a trojan installer hidden in thousands of torrent files. The installer, often disguised as popular video games such as Grand Theft Auto (GTA) and Assassins Creed, forcibly installs malicious web extensions for Google Chrome and Edge.
The malicious installers identified by ReasonLabs primarily deliver one of three different harmful web extensions for Google Chrome and Edge, all posing as Virtual Private Networks (VPNs). Google has removed malicious extensions from the Chrome Web Store but by that time, the offending extensions (netPlus, netSave, and netWin) had together accumulated nearly 1.5 million installs.
The trojan installer, often presented as setup.exe and labeled “by Igruha,” is commonly distributed through torrent downloads claiming to be popular video games, including Assassins Creed, GTA, The Sims 4, and Heroes 3.
Researchers have identified over 1,000 torrent files delivering the same setup file, with a common signer name, “SPICE & WOK LIMITED.” These installer files range from 60MB to over 100MB in size. The installer utilizes a sophisticated method, modifying browser files via the registry key “SOFTWARE\Google\Chrome\PreferenceMACs\Default\extensions.settings” to install the malicious web extensions without the user's knowledge or consent.
The three extensions come with a massive JavaScript code comprising over 20,000 lines. Although the full extent of the code's activities remains unclear, researchers have confirmed that these extensions are not just fake VPNs but also carry out cashback activity hacks. To ensure success, the extensions disable other cashback extensions on infected browsers while presenting a genuine VPN user interface with limited functionalities to maintain a facade of legitimacy.
All three extensions are in Russian, suggesting that they are aimed at Russian-speaking users. ReasonLab said it identified thousands of infected users across Russia, Ukraine, Kazakhstan, Moldova, and other countries with significant Russian-speaking populations.