Fake Chrome Update Malware

Поделиться
HTML-код
  • Опубликовано: 28 окт 2023
  • Malware masquerades as Chrome/Edge/Firefox update by injecting javascript code into hacked wordpress sites! Research: labs.guard.io/etherhiding-hid...
    Get Guardio (50% off with our special sponsor link): guard.io/pcsecurity
    Buy the best antivirus: thepcsecuritychannel.com/best...
    Join the discussion on Discord: discord.tpsc.tech/
    Get your business endpoints tested by us: tpsc.tech/
    Contact us for business: thepcsecuritychannel.com/contact
  • НаукаНаука

Комментарии • 622

  • @MordecaiTheAwesomeBluejay
    @MordecaiTheAwesomeBluejay 7 месяцев назад +927

    This is why Ad blockers are a MUST for everyday web browsing. Yet Google wants to take that away from us

    • @3TDEV01
      @3TDEV01 7 месяцев назад +8

      Not an ad

    • @greatveemon2
      @greatveemon2 7 месяцев назад +42

      Just don't visit malicious or 'you don't know' site. Also Google only discourage you to not use adblock on YT and not in other site. I still have all the adblock turned on on other site just to prevent something like this.

    • @andrei.01
      @andrei.01 7 месяцев назад +165

      @@3TDEV01 It's a pop-up. Pop-ups can host any content: ads, scams etc

    • @paulmoadibe9321
      @paulmoadibe9321 7 месяцев назад +8

      they already did with YT ...

    • @tiranobanderas5655
      @tiranobanderas5655 7 месяцев назад +94

      @@greatveemon2 "just don't visit malicious sites" bruh what? Just don't browse at all then. What kind of logic is that? Like, I'm sorry but if your solution to not pressing suspicious looking buttons and links is not to enter suspicious looking sites, then I'm sorry but your access to a device with internet access should be revoked. How can there still be people like you on the internet?

  • @wangjiefan8939
    @wangjiefan8939 7 месяцев назад +39

    Imagine my confusion when I got that popup on Firefox 💀

  • @PidroBondar
    @PidroBondar 7 месяцев назад +230

    This just goes to show how important it is to NEVER open an .exe file until you are 100% sure it comes from a reputable source

    • @UnknownX.Trash-Gxng6
      @UnknownX.Trash-Gxng6 7 месяцев назад +4

      How to remove this bad update virus thing

    • @user-fd4il6pi9i
      @user-fd4il6pi9i 7 месяцев назад

      what @@UnknownX.Trash-Gxng6

    • @user-fd4il6pi9i
      @user-fd4il6pi9i 7 месяцев назад

      You can't remove it if you ran it that's it@@UnknownX.Trash-Gxng6

    • @jimmyhopkins1
      @jimmyhopkins1 7 месяцев назад

      ​@@UnknownX.Trash-Gxng6reinstall windows buddy

    • @meltymooncakes
      @meltymooncakes 7 месяцев назад +3

      im gonna run every exe file (i dont use windows, i use linux)

  • @Sool101
    @Sool101 7 месяцев назад +227

    Funny you mention that, just yesterday some big phone manufacturer flagged google as malware. Following the forums was kind of hilarious. But that aside.

    • @yotoprules9361
      @yotoprules9361 7 месяцев назад +23

      I have seen that on my Huawei and Honor devices (it is an Honor 20 so it still has Huawei software on it).

    • @Sool101
      @Sool101 7 месяцев назад +2

      @@yotoprules9361 hope you fixed it by clearing optimiser cache?

    • @yotoprules9361
      @yotoprules9361 7 месяцев назад

      I just hit "ignore" and the checkbox so it doesn't prompt me again. @@Sool101

    • @madeidiot2430
      @madeidiot2430 7 месяцев назад +4

      where you see the forum? because i see notif in my phone huawei google as malware and i can't uninstalling, and i dont know what must i do now

    • @Sool101
      @Sool101 7 месяцев назад

      @@madeidiot2430 you have to go to: settings - apps - optimiser - clear cache

  • @XyukonR
    @XyukonR 7 месяцев назад +311

    I actually ran into this on a website a few weeks ago. It looked totally suspicous to me and the blue button to "Update Chrome" had some very strange address so I closed the page and notified the owner immediately. I consider myself pretty tech savy and I almost fell for it so the average person would easily fall for something like this.

    • @everypizza
      @everypizza 7 месяцев назад +32

      I don't like updates so I just close it

    • @tpd1864blake
      @tpd1864blake 7 месяцев назад +8

      I would have looked at the url and saw that it took me to some completely random website that isn’t associated with Chrome at all

    • @everypizza
      @everypizza 7 месяцев назад

      @@tpd1864blake im not that smart

    • @benx2230
      @benx2230 7 месяцев назад +31

      You use Chrome. So you're not as tech savvy as you think you are.

    • @fus3n
      @fus3n 7 месяцев назад +11

      I dont think there will be any point in history where a browser will show a popup and block you and tell you to update it so you can view the content, it would rather break the website and show nothing.

  • @bartwaggoner2000
    @bartwaggoner2000 7 месяцев назад +174

    OK, that was pretty scary as my wife asked me about doing an update like this a few days ago, and luckily I said let the auto update do it. Thank you!

    • @HazyJ28
      @HazyJ28 7 месяцев назад +16

      chrome will always update automatically. All browsers do. If you want to do it manually, go to settings>about chrome. If it ever pops up bc of a URL/while on a website like the above example, it's definitely fake and probably malware masquerading as legitimate.

    • @lovelost234
      @lovelost234 7 месяцев назад +4

      I'm glad you said that, because after watching the video, I was thinking 'So, how should a person deal with this problem?'. Thank you for the answer.

    • @RunicSigils
      @RunicSigils 7 месяцев назад

      ​@@HazyJ28I don't know why so many of you keep saying that like you haven't turned it off like you should.

    • @gelmir7322
      @gelmir7322 7 месяцев назад +2

      Not all updates bring good things.
      Sometimes it will be bug ridden, sometimes it has compatibility issues.
      Sometimes it will introduce terms of service that you do not agreed or consent with (like DRMs for apps and games)
      So I will alway turn auto-update off.
      Then I will join discussion forums and check-out if other users/subsribers are having issues with any latest updates before I do the update myself.

  • @thchaoticcorporation
    @thchaoticcorporation 7 месяцев назад +37

    Advertisers need to be held liable for all of the malicious ads they put up.

    • @AlienXtream1
      @AlienXtream1 7 месяцев назад

      in theory they are. in practice it can be a lot harder to track down the parties involved and they are often in other places around the world like Russia or China which means prosicution is even harder.

    • @RianQuenlin
      @RianQuenlin 7 месяцев назад +3

      @@AlienXtream1 Then go up the chain. Can't go after Lao Chang in China? Go after the company serving the ad, go after their hosts, go after whoever handles payments. Find an ass to kick.

    • @merasmus9992
      @merasmus9992 6 месяцев назад

      @@RianQuenlindifficult when they could give a portion of said funds to their government, thus making it against their ideals to hand over free funding

    • @zerosam5541
      @zerosam5541 6 месяцев назад

      That will never happen

  • @NopWorks
    @NopWorks 7 месяцев назад +185

    This is a reminder that "your browser comes with automatic updates" PSA that we sometimes see isn't out of nowhere.
    People need to know that every browser these days updates automatically and popups like these are all bogus.

    • @icantcomeupwithnames469
      @icantcomeupwithnames469 7 месяцев назад +5

      Mine doesn't (Librewolf), but I just update it when I do my regular checks with winget.

    • @RunicSigils
      @RunicSigils 7 месяцев назад

      No one with any sense of security has their browser (or anything for that matter) doing automatic updates.
      People screw up. You don't want to be a victim of their screw up. Depending upon the prevalence of the thing and how you use it you're talking at least two to four weeks before you should be touching an update so you have plenty of time to know whether or not they're likely screwing you over with it.
      The real point is that you should know that the browser doesn't pop up a full on webpage asking you to update.

    • @ultimatedarkkiller7215
      @ultimatedarkkiller7215 7 месяцев назад

      ​@@icantcomeupwithnames469It does automatically update now if u also apply Librewolf-WinUpdater

    • @JCO2002
      @JCO2002 7 месяцев назад +1

      Not with Linux Mint and automation disabled.

    • @ultimatedarkkiller7215
      @ultimatedarkkiller7215 7 месяцев назад +4

      @JCO2002 Ah, I meant for windows users, I use arch so I manually update too

  • @bastardgoose
    @bastardgoose 7 месяцев назад +26

    Step one: don't click every download button you see. Maybe Google should make it clear that chrome updates itself without needing to download random exe files. Maybe they should do something similar to Microsoft, in terms of Microsoft actively detects when you go to a Chrome download to essentially beg you to not. They should detect fake chrome, download pages and warn users.

    • @dustycrophopper2743
      @dustycrophopper2743 5 месяцев назад +1

      correct, google and all these tech companies need to issue a press release

  • @a.p5193
    @a.p5193 7 месяцев назад +34

    This why adblock will never die

  • @Buzzygirl63
    @Buzzygirl63 7 месяцев назад +178

    Thank you for educating us and keeping us safe!

    • @HazyJ28
      @HazyJ28 7 месяцев назад +6

      No doubt, his channel is required reading for my family 🫠😂😂

  • @publicalways
    @publicalways 7 месяцев назад +10

    Reading through the comments, it seems like so many people still have no clue. This problem is not limited to Chrome, or Firefox, or Windows, or Linux. It is a JavaScript thing, so it could happen on any system.
    I'll try to summarize and keep it simple for those not as techy.
    When you're browsing the web and a pop-up appears telling you need to update your browser, do NOT click on it. Not even when you're browsing your frequently visited sites because these sites could have been hacked to send you the fake prompts.
    The malware may steal your accounts' information in split seconds, then unload itself before anti-virus could detect them.
    If you need to update your browser or *any* software for that matter, always go through the official website only, and not by some 3rd party or "convenient" pop-up.

  • @FlyingFun.
    @FlyingFun. 7 месяцев назад +13

    Let auto update do updates and click nothing especially downloads.
    Man it is dangerous out there these days.

  • @CoolJosh3k
    @CoolJosh3k 7 месяцев назад +46

    There are people who will see their anti-virus block it, then decide to override that decision thinking their AV is wrong because it is “just a Chrome update from Google.”
    I think it best if the AV silently blocks it and then if checked for info it shows why.

    • @JCO2002
      @JCO2002 7 месяцев назад

      Anti-virus? Linux.

    • @CoolJosh3k
      @CoolJosh3k 7 месяцев назад +2

      @@JCO2002 If only that was true. Virus still very much exist for Linux, but the situation is quite different. I am inclined to think Linux is much safer, but only because of how it works when used right.

    • @JCO2002
      @JCO2002 7 месяцев назад

      @@CoolJosh3k Inclined to think? When used right? You only need anti-virus applications for Linux if you run a server, and that's just to stop Windows users from transferring viruses from one to another. Can you give me one example of a Linux user getting any type of virus on their machine?

    • @CoolJosh3k
      @CoolJosh3k 7 месяцев назад

      @@JCO2002 That would take time and research to dig up examples, but what matter anyway is the existence of the possibility. Just like leaving one’s front door unlocked all year, you can still have no issues due to so many factors (like being a target).
      I can imagine a case, for an example, where a Redline Stealer infects a Linux system of a popular content creator.
      I would still choose Linux over Windows instantly if deciding based on virus risk.

    • @JCO2002
      @JCO2002 7 месяцев назад

      @@CoolJosh3k "I would still choose Linux over Windows instantly if deciding based on virus risk." Then we're on the same page. It's also a superior operating system, at least the distro I use, Mint 21.2, is.

  • @wh17efox
    @wh17efox 7 месяцев назад +11

    good that i know how actually update browser properly, but this ”kind of update” is very scary

  • @kozuta8858
    @kozuta8858 6 месяцев назад +3

    This happened to me but from a crack file, I was so stupid and confident about my knowledge since I also use 2FA on all my accounts. I ran the exe file and nothing happened. Then, i wasn’t aware about things like session hijackings and suddenly my youtube has weird ass watch histories, good thing I was able to change it quickly

  • @skystoyhunts7225
    @skystoyhunts7225 7 месяцев назад +13

    I remember seeing a fake malware Firefox update that kept popping up years ago when I was using the real Firefox. I accidentally downloaded it not knowing it was fake. I was a kid when I did it and i realized that it was a malware because my grandpa told me it was and I told him I didn't know because it looked real

  • @MatibazPL
    @MatibazPL 7 месяцев назад +29

    Could you do a tutorial on how to detect a virus that isn't visible in process explorer, autoruns, tcpviewer etc? Is it possible to do this in a simple way? EDIT. I forgot to mention that I would like to do this manually. As you know yourself, antivirus doesn't always detect everything.

  • @Punisher0362
    @Punisher0362 7 месяцев назад +9

    That's scary how convinced I would have been by that update page, I would have been really sus of the downloaded file, though.

  • @andrei.01
    @andrei.01 7 месяцев назад +14

    From my personal experience, Bitdefender would not even approve this download. The file would end up directly in quarantine ☺

    • @PankajDhande
      @PankajDhande 7 месяцев назад +1

      That is exactly I don' rely on Windows defender. You saw in this case Windows defender was way too late to detect the threat, blocking it is another question.

    • @lingbg2502
      @lingbg2502 6 месяцев назад

      ​@@PankajDhandebetter late than nothing
      Maybe MD had problems scanning or blocking it quickly

    • @charliek7896
      @charliek7896 4 месяца назад

      @@lingbg2502 "Maybe MD had problems scanning or blocking it quickly" THAT'S WHAT THEY ARE SAYING. IT'S ABSURD TO DEFEND AN ANTIMALWARE PROGRAM THAT DOESN'T WORK AS WELL AS OTHER ANTIMALWARE PROGRAMS DO.

  • @Sypaka
    @Sypaka 7 месяцев назад +3

    If a webpage notifies me my browser is outdated, I just ignore that (especially, when I just updated).
    This stuff has been around since ages (For Java, Adobe Flash) and no one should trust it at all.

  • @stevebabiak6997
    @stevebabiak6997 7 месяцев назад +8

    Since they can detect the browser that is being used, this same sort of attack / vulnerability can affect any and all browsers (by just displaying the name of the browser rather than “Chrome”), since it tries to take advantage of unsuspecting users.

  • @RaidenRkD
    @RaidenRkD 7 месяцев назад +9

    Another thing to look out for is the site URL when that update page pops up. Definitely not a Google link. And if it pops up in a separate window where it's hidden, a definite no.

    • @javieremrique6086
      @javieremrique6086 7 месяцев назад

      that's exactly what I was thinking, this is not google url, so is so easy to see

  • @onedeadboy5680
    @onedeadboy5680 7 месяцев назад +4

    What's wild about these kind of attacks is that some variants can do their job without any privilege escalation. As long as web browsers use their host OS current user session and credentials to "lock" saved passwords, it will never be secure to keep your passwords saved in them. And attacks targeting opened browser sessions are becoming more common too. Crazy stuff

    • @Sypaka
      @Sypaka 7 месяцев назад +1

      They can force close programs, if necessary. For example Discord saves its token when closed - the best moment to steal the token, if a program is designed for that.

  • @IGLXenix
    @IGLXenix 7 месяцев назад +8

    This is why I go directly to the settings menu within chrome or any/every other program to check for updates that has it, never follow a pop up for any kind of download or update, especially if the program doesn't normally stop operating due to a lack of update or if there's a new update available.

  • @UtherV
    @UtherV 7 месяцев назад +3

    Thank you for the in depth rundown! I do have a question though: how effective are these types of stealers when using Firefox's Master password or Edge's 2fa? Thanks!

  • @BradTheThird
    @BradTheThird 7 месяцев назад +2

    Interesting that this came up. My Chrome has been telling me that it can't update for the past few days, and I had a moment the other day where I enabled cookies for something and then I kept getting windows notifications saying my McAfee anti-virus had detected a million viruses. I don't have McAfee installed. I deleted all cookies because I knew what I had clicked and it stopped. But I'm sort of suspicious now.

  • @imahotdogdonteatme8722
    @imahotdogdonteatme8722 7 месяцев назад +4

    I like to think I wouldn't ever fall for stuff like this but considering the sophistication of some of these attacks I 100% could see myself clicking on one of these when I'm tired or in a rush.

  • @shodanki3736
    @shodanki3736 7 месяцев назад +2

    and this at a time when YT forces ADs which themself can be infected.

  • @F_Around_and_find_out
    @F_Around_and_find_out 7 месяцев назад +6

    At least on firefox the update is automatically downloaded in the background as soon as you open it, and you can check by open the 3 stripes on the top right corner, go to help and About to see which version you have. That is the proper way to do things, don't do what a popup tells you to do A to get B. The developers automatically update your browser when possible, in the background.

    • @Rickyfffff
      @Rickyfffff 7 месяцев назад

      Not just Firefox most browsers do this

  • @LouisSerieusement
    @LouisSerieusement 7 месяцев назад +8

    Depending on the time of the day, I could have fallen for the "popup"
    But I would never click a .exe file for updating anything

  • @nikosxrim
    @nikosxrim 7 месяцев назад +1

    Great video, spreading awareness on such topic is very significant. I would likely fall for it because it seems very convincing

  • @MarcCastellsBallesta
    @MarcCastellsBallesta 7 месяцев назад +6

    I will show this video to my students tomorrow!

  • @aymericrichard6931
    @aymericrichard6931 7 месяцев назад +57

    Some white hackers have found ways to get control of a windows host server from the windows virtual host. So testing in a VM is still dangerous even so this specific vulnerability has provably been fixed since.
    (Was a virtual box vulnerability)

    • @TheDiamondHit
      @TheDiamondHit 7 месяцев назад +15

      This has actually been a thing for a long time. Especially in the RATTING scene.

    • @slaydog5102
      @slaydog5102 7 месяцев назад

      ​@@TheDiamondHit✅

    • @H8RSAPPRECIATE
      @H8RSAPPRECIATE 7 месяцев назад +4

      Lmao I’m so cautious I wouldn’t even run in virtual machine or connected to my wifi lol

  • @breakingaustin
    @breakingaustin 7 месяцев назад +1

    So many people can be saved by just knowing never to open a .exe file unless you initiated it yourself or you know where it's from.. Adblock is invaluable in this example as those pop-ups would be most likely blocked.. There has been multiple times where I have tried to download something and notced it was a weird .exe file with a different name and stopped it in time, thanks to videos like this. Love the work man, keep it up.

  • @blueridgeocean
    @blueridgeocean 7 месяцев назад +4

    I remember these back in 2012-2013 on the macbooks. Our schools website got hacked and everyone who visited got a update pop-up. Most people downloaded it.

    • @SW73_
      @SW73_ 7 месяцев назад

      Wow...

  • @V530-15ICR
    @V530-15ICR 7 месяцев назад +2

    If that happened to me I would just look for another tutorial or see if there was a cached/archived version of that website, because I don't want to update.

  • @sgmc420
    @sgmc420 6 месяцев назад

    Literally JUST happened to me and I closed the browser immediately. I am beyond glad I watched this video weeks prior. Thank you.

  • @DNL_Original
    @DNL_Original 7 месяцев назад

    I have an question i followed an tut how to see if someone hacked your pc by typing netstat in cmd because in last time my laptop is shuting down automaticly and sometimes i cant log in my antivirus programms say nothing (im using kaspersky premium and win defender) but when i type netstat in cmd 1 link ends with 7474 insted https or http PLEASE REPLY HOW TO REMOVE THIS HACKER OR WHATEVER THAT THING IS I WHOULD BE HAPPY

  • @gabolm
    @gabolm 7 месяцев назад +11

    In your video, you said that they probabily steal the passwords saved on the browser. How about on password managers? Extensions or Windows based ones? I know they usually are encrypted on device, but still, are there a chance they can get to it?

    • @stratvar
      @stratvar 7 месяцев назад +8

      Yes and no. The passwords saved inside your password manager would be safe. What wouldn't be safe is your password manager's main account itself in case you have chosen to always be logged in to it from your computer (i strongly advise *against* it). If that gets compromised then yes, they will have access to those too.

    • @gabolm
      @gabolm 7 месяцев назад

      @@stratvar So they would have the "session cookie", okay thanks for answer!

  • @Limitless-nt7xz
    @Limitless-nt7xz 7 месяцев назад +6

    Thanks for keeping us informed my dude!!!

  • @Romanitto
    @Romanitto 7 месяцев назад +1

    I think people who checks email address at work to make sure if it's not a fake or scam will also realize if they need an update for browser and usually browser will do it automatically

  • @Graham6410
    @Graham6410 7 месяцев назад +1

    Reminds me of one of those popups that says it's an update for your phone.

  • @dennisp8520
    @dennisp8520 7 месяцев назад +1

    A question I am curious about when it comes to the passwords being stolen would it be able to steal passwords that are inside a password manager like 1Password?

  • @getawaydriver1015
    @getawaydriver1015 7 месяцев назад +2

    Set your settings for notification system to high alert and make sure you have system protection on in system configuration for configuration to high as well and turn off the remote tcp settings known as connection crossing in world connections in system configuration. It'll make it a lot more harder for malware and people to get in on your computer. And if you sat admin administrator for certain settings and makes it even harder for them to get into the system. Cuz then they need administrator access but then you have all your configuration so it makes it even harder for configuration access and administrator. Access through remote connections .. my CPU runs at 10%

  • @hotmixer2010
    @hotmixer2010 7 месяцев назад +2

    Never had this problem ever since switching to quad9 DNS and cloudflare DNS with malware filtering

  • @JustJanitor
    @JustJanitor 7 месяцев назад

    Thanks for sharing these videos. Just found your channel

  • @claycassin8437
    @claycassin8437 7 месяцев назад +4

    Good thing I have never used a Chromium based browser. Wise move on my part. My second one was switching to Linux.

  • @Mars-lf1pz
    @Mars-lf1pz 7 месяцев назад +1

    Where can we download the Sysinternals tool that you were using to demonstrate the infected file?

  • @dend1
    @dend1 7 месяцев назад +4

    Coulda swore I saw something like this and decided against it because I didn't want to reset my browser

  • @Akotski-ys9rr
    @Akotski-ys9rr 7 месяцев назад +1

    I would probably think it’s fake because update google doesn’t just pop up like that in the same tab

  • @AinzOoalG0wn
    @AinzOoalG0wn 7 месяцев назад +3

    ok so the malware executes then hides itself so later if u check process explorer, you wouldnt be able to see it show the total virus to indicate anything bad happens.
    so question is, how would u know? people would be oblivious to this. not to mention some malwares also hide their activity when you open task manager, and goes dormant. but later when u close it, it's back to ramping up cpu to 100% up to no good.
    would be useful if you taught how us users would be able to detect that and also remove.

  • @generalsourabh5809
    @generalsourabh5809 7 месяцев назад

    Hey Just quick question I have "Control folder access: Enabled" on MS defender mean, even if this run windwos defender will flag it as trying to access my inner root folder hence it will be bloked right??

  • @mirrorportal1587
    @mirrorportal1587 7 месяцев назад +1

    This reminds me of the good old flash player installer, thanks for covering this program

  • @charleshines2142
    @charleshines2142 7 месяцев назад +1

    If you ran Wireshark it would catch all of that. It might not decrypt anything easily but you would have the encrypted file and any IP addresses it went through.

  • @CODE_Abyss
    @CODE_Abyss 7 месяцев назад

    More reasons why I only ever update my browser when the actual update button appears at the top of the browser. I would never manually download a browser update.

  • @davidbwa
    @davidbwa 7 месяцев назад

    I did not know about this but I initiate all my updates. Usually manually or with some programs I let them auto update. But even an auto update will not be going to a fake web site. It seems like the same general good rule of thumb that applies to emails, texts, telephone calls and everything. If it is initiated from the outside, be very cautious. It has been years since I retired from IT but even back in the day when auto protection was not as good, the majority of times I was helping someone with malware it was self inflicted.

  • @mantikhatasi
    @mantikhatasi 7 месяцев назад +6

    who updates browser from website. browser does itself.

    • @ChristophHoward
      @ChristophHoward 7 месяцев назад +1

      Probably enough to make it worth making this

    • @ent2220
      @ent2220 7 месяцев назад

      It's a Windows user thing. And so are auto updates too by the way, the way those browser update on windows by default (I believe). I don't like either. I shall only update when I choose to, without any notice, popup or notification presented to me, and I shall only do so using my package manager.

  • @MrSinsglory
    @MrSinsglory 7 месяцев назад +1

    Thanks for keeping us informed.

  • @Randomdud751
    @Randomdud751 6 месяцев назад

    A few days ago I actually got a pop-up like that. It told me to update Chrome if I wanted to go further... but I was using Brave...

  • @Sam_Saraguy
    @Sam_Saraguy 7 месяцев назад +5

    That's a nasty one, thanks for the heads up.

  • @WaqarAslam2000
    @WaqarAslam2000 7 месяцев назад

    What methods are used to hack wordpress websites? What method or methods were used to inject those javascript codes in the articles?

  • @HR-wd6cw
    @HR-wd6cw 7 месяцев назад

    I think I ran into a website that was trying to do this but my AV (ESET) blocked it (doing more research it found some code in a WP theme that someone used). However I never found out if this was the case because my AV simply shut down the connection and blocked the entire site.
    For updates, generally I just download the installer again and run it, since it will update the browser in question if it finds an out-of-date version in most cases.

  • @apersimmon
    @apersimmon 7 месяцев назад +1

    This is why I don't use cookies, because I don't trust my self not to accidently install cookie and other credentials logging virus because of how common they are.

  • @ShadowDrakken
    @ShadowDrakken 7 месяцев назад +1

    how does one go about hardening their WordPress to avoid this kind of infection?

  • @tayib7665
    @tayib7665 6 месяцев назад

    I am not so tech savy, I have a question :bitdefender or kaspersky installed on my pc would have blocked that file or not?

  • @SFBenjaminK
    @SFBenjaminK 7 месяцев назад

    WOULD u plezzz do the comparison video between Bitdefender , Kaspersky & Norton which one is THE BEST & comes out as winner ....also what is UR FAV or the BEST Antivirus total security software OF this year!

  • @factoraavion2874
    @factoraavion2874 7 месяцев назад

    Another rule of thumb is, you update your browser in the about section in the browser itself and not downloaded on any website or ad .

  • @HulkSmashedU
    @HulkSmashedU 2 месяца назад

    Does it leave anything on your computer if you happen to click on it? If so where to go and delete it.

  • @TinyDeskEngineer
    @TinyDeskEngineer 7 месяцев назад

    If I click on a button that says "Update Chrome" and I _download an executable_ I am not visiting that site as long as I remember that.

  • @mr-eggman
    @mr-eggman 7 месяцев назад

    I have been recently getting some UAC prompts about Google chrome update randomly on my computer when chrome is closed. Every time I click yes. Is this also a virus?

  • @FireCrauter
    @FireCrauter 7 месяцев назад

    Why didn't you show the network traffic like wireshark or fiddler?

  • @albertjones1386
    @albertjones1386 7 месяцев назад

    It amazes me that in following your instruction, there is nothing the same in my computer which is running Windows 11. By searching, I have found "properties" and I found "Advanced system setting" but I can not find the page next that you talk about. Help! I want to check. By the way, I don't think I have seen the Google update you are referring

  • @johnyu3463
    @johnyu3463 7 месяцев назад

    Hello sir, i got this on my pc and everything was stolen, but my problem now is that my pc starts running slow after everything was stolen. Can I ask you where could i start to clean my pc?

  • @8DBeats.
    @8DBeats. 5 месяцев назад

    i got an ad for chrome’s malware protection before this video

  • @ShokudaikiriMitsutada
    @ShokudaikiriMitsutada 7 месяцев назад +4

    What a blessed channel!

  • @djmccullough9233
    @djmccullough9233 7 месяцев назад

    it may just be me, but ive seen these "you need to upsate your browser to view this " or "you need this plug in to view this" for years. they really arent that convincing. im suprised to see this classified "malware" instead of "really basic tactic to mess up people who have literally never surfed the web before."

  • @tbote
    @tbote 7 месяцев назад

    So only update by going to about and ignore popups that say update correct?

  • @horde479
    @horde479 7 месяцев назад +1

    i think i might have installed it, i did found it sus that i need to install an installer for update as it happens in background mostly but the popup appeared automatically in the browser as soon as i opened it twice and not on a site so i did it and seemed petty legit too. Also after i ran the program unlike in the video chrome seemingly installed/reinstalled some stuff and a new "what's new in the update" window appeared. and yeah it happened a while ago like 2-3ish weeks
    So i was curious that was it legit or i messed up

  • @FlameForgedSoul
    @FlameForgedSoul 7 месяцев назад

    Except Chromes update prompt appears in the top right of the browser bar... because it updates automatically in the background.

  • @VascovanZeller
    @VascovanZeller 7 месяцев назад +2

    How does this malware steal passwords? Is it the memorized passwords on the browser (isn't that encrypted?) or the cookie for the sessions?

    • @U20E0
      @U20E0 7 месяцев назад

      browsers' password managers all have horrible security (never use them), and the cookies can just be stolen since that's not even considered sensitive data (try to not use those either if given the option)

    • @RussGreeno
      @RussGreeno 7 месяцев назад

      Unfortunately not with Chrome on Windows, any app can suck passwords and cookies from Chrome without it asking for any authentication. Microsoft Edge caught me out recently and one click, all my Chrome data was sucked into Edge.

  • @a68k_de
    @a68k_de 7 месяцев назад +1

    when adblockers can safe your computer life
    oh the websites hate adblockers...

  • @rickknowles9620
    @rickknowles9620 7 месяцев назад

    How will I ever find out it this has happened? Would malware bites pick this up? I have the browser guard and paid pro version?

  • @atomotron
    @atomotron 7 месяцев назад

    If any webpage would do that to me, just reading the page and boom it spits popup in my face, the first thing I do is open the developer tools and ufking kill the element with the popup. Restore the overflow property on the page body, then continue reading.
    If the page would struggle more, and somehow make it absolutely impossible to get to the content without registering, the domain goes straight up into the blacklist. I don't need sites that track me, bomb me with messages, and feed me some "personalized enhanced truth", thank you very much.

  • @IsraelBelongToChrist
    @IsraelBelongToChrist 7 месяцев назад

    What can i do if someone break in to my house and has the ability to get in to my pc over and over again?

  • @kafadek825
    @kafadek825 7 месяцев назад

    Question: I know info stealers steal login details stored in browsers. Does anyone know if they also steal information from browser extensions? eg. can an infostealer steal information from a password manager browser extension like Bitwarden?

  • @Enjoymentboy
    @Enjoymentboy 7 месяцев назад +1

    I work on the theory that if a site tells me to update my browser or turn off my adblocker then I'm not going to that site irrespective as to whether it is a legit site or not. You want me to visit your site then just let me in. If I have to do a dance then I'll go elsewhere. That's the beauty of the internet. There's always another option waiting.

  • @jacop551
    @jacop551 7 месяцев назад +1

    The scary thing is that it is signed. How can it be signed?

  • @noxsamus397
    @noxsamus397 7 месяцев назад

    and this is why i don't use manual updates, i'v set it to auto and as far as i know only the real update can auto update, all i see is when i first start the webapp is "its has bin updated to the latest version".
    i also hover over all links i'm about to click to see where it leads, if it looks just a tad iffy its a no click for me. same goes for mail, never send me a link because i'll NEVER click links inside mails EVEN if it comes from FRIENDS.
    yea i'm this paranoid, and even me do get infected from time 2 time, so i'm constantly changing how i use internet.

  • @henryijeoma
    @henryijeoma 7 месяцев назад

    it should be common knowldge that chrome will never pop up on a full page asking you to update

  • @InvictusCanuck
    @InvictusCanuck 13 дней назад

    I clicked the update button. But never ran the script, deleted it from my downloads and recycling bin. Am I good?

  • @mienoni5330
    @mienoni5330 7 месяцев назад +1

    Is it me or Kaspersky prevents the Guardio article from opening?... It claimed it stopped something from downloading yet nothing show up in the logs...

    • @mienoni5330
      @mienoni5330 7 месяцев назад

      @@PCLinke Did Kaspersky delete your report log afterwards? Because it did for me and no web report remained, not even the old ones, so I'm left wondering what did 8it actually stop from downloading..

    • @PCLinke
      @PCLinke 7 месяцев назад

      ​@@mienoni5330 No it did delete the logs, reset settings or reinstall Kasper if there an issue, here is what is stopped downloading:
      Type: Trojan
      Name: HEUR:Trojan.Script.Generic
      Precision: Heuristic Analysis
      Threat level: High
      Object type: File
      Object name: etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts-65ea78efad16?gi=4edbf4706ca3
      Object path: labs........

  • @Vichingo455
    @Vichingo455 7 месяцев назад

    Well not a surprise. Once I got a pretty damn page with a fake Windows desktop, an error saying I have to install a program to cleanup the system because there is no storage left with as well cortana voice as tts. As well they were the first times for me using a computer but I didn't fall for that.

  • @rindehack227
    @rindehack227 7 месяцев назад

    Which Antivirus would you prefer for your Mobil Phone and Pc ? Or waht do you have?

  • @henikmayer1453
    @henikmayer1453 7 месяцев назад

    Thank you for the info - I'm asking me if X operation systems would help ? THX

  • @camboi6103
    @camboi6103 7 месяцев назад

    ironically enough, chrome never prompts the user to update, it updates whenever and just tells the user that it has updated

  • @mikengtw
    @mikengtw 7 месяцев назад +1

    Great info I like it keep me updated 😊👍🏼

  • @RedBeardedJoe
    @RedBeardedJoe 7 месяцев назад

    well the thing is though for me i always check on Microsoft edge under settings check for updates

  • @WinVR
    @WinVR 7 месяцев назад

    I had a similar thing happened to me, I verified for a discord server, and it brought me to a link. The link was saying I needed to update my adobe.

  • @daleksandrov
    @daleksandrov 7 месяцев назад

    Whats your opinion about ESET NOD32 ? Thanks