No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

‘Shampoo’ ChromeLoader Variant Difficult to Wash Out

June 19, 2023
in Protection
0
'Shampoo' ChromeLoader Variant Difficult to Wash Out



Fake websites advertising pirated video games, films, and other wares are spreading a new variant of the ChromeLoader malware dubbed “Shampoo,” that is anything but clean: It steals sensitive data, redirects searches, and injects ads into a victim’s browser session.

Researchers from HP Wolf Security have been tracking the new campaign, which appears to have been active since March and distributes malware similar to the original ChromeLoader — first discovered in May 2022 — but that’s noticeably harder to wash out of the proverbial IT hair thanks to multiple persistence mechanisms, they said.

The goal of the first version of ChromeLoader was to install a malicious Chrome extension for advertising, a process that includes “a particularly complex infection chain” that begins with victims downloading malicious ISO files from websites hosting illegal content that hijack browsers, wrote Jack Royer, an HP malware analyst intern, in a post on the HP Threat Research Blog published this week.

“ChromeLoader used in the Shampoo campaign is very similar; it tricks victims into downloading and running malicious VBScript files from websites, eventually leading to the installation of a malicious Chrome browser extension,” he explained. “This campaign is very similar to ChromeLoader, in terms of its infection chain, distribution, and objective,” with the two sharing code similarities and the ad-monetization feature.

One notable feature of Shampoo that’s different than the original ChromeLoader is how it uses the browser’s Task Scheduler to achieve persistence, by setting up a scheduled task to re-launch itself every 50 minutes, they said.

The script runs a PowerShell script that sets up the scheduled task, running a looping script every 50 minutes that downloads and runs another PowerShell script, the researchers said. This script downloads and installs the malicious ChromeLoader Shampoo extension that, once attached to a Chrome session, starts sending sensitive information back to a command and control (C2) server.

“This persistence mechanism allows the malware to remain active despite reboots or the script being killed by a security tool or user,” Royer wrote.

Inside the Shampoo ChromeLoader Infection Chain

Users who encountered Shampoo did so by downloading illegal content from the Internet, such as movies, video games, or other files, from websites that offer pirated files, the researchers said. Victims are tricked into running malicious VBScripts that they think are pirated wares — for example, Cocaine Bear.vbs or Your download is ready.vbs — which triggers the infection chain, the researchers noted.

“The extension is heavily obfuscated and contains many anti-debugging and anti-analysis traps,” with its author appearing to have used a free online JavaScript obfuscator to make the malware harder to detect, Royer wrote.

Other malicious activities that ChromeLoader Shampoo carries out on a victim’s machine include disabling search suggestions in the address bar; redirecting Google, Yahoo, and Bing searches to the C2; logging the victim’s last search query in Chrome’s local storage; and logging the last search query in Chrome’s local storage and preventing victims from accessing chrome://extensions by redirecting them to chrome://settings, likely to stop them from removing the extension, the researchers said.

The persistence mechanism that sets up the scheduled looping task also unregisters a list of tasks prefixed with “chrome_” — such as “chrome engine,” “chrome policy,” and “chrome about,” the researchers noted. “This is likely done to remove any previous or competing version of the same malware,” Royer wrote.

Be Wary of Illegal Downloads

Though the first version of ChromeLoader was similar to Shampoo in that it was mainly aimed at hijacking browser sessions and stealing victim data, it has since evolved into a more dangerous threat, with attackers now using it to drop ransomware, steal data, and crash systems at enterprises.

It’s unclear if the Shampoo variant also will be leveraged in this way in the future. However, the researchers advised that people shouldn’t take chances, and provided tips for how to avoid infection as well as a list of indicators of compromise in the post.

One obvious way to avoid compromise by the Shampoo variant is not to download pirated material from the Internet, and to avoid downloading any files from untrusted websites in general, they said. This is particularly true for employees using Chrome in a corporate environment, who should be particularly wary of downloading anything from the Internet via a corporate network (or onto a shared work/personal device), lest it spread throughout an organization.

Organizations should also configure email gateway and security tool policies to block files from unknown external sources as added protection, advised Patrick Schläpfer, malware analyst at the HP Wolf Security threat research team, in a press statement.

Editorial Team

Editorial Team

Related Posts

The Best Books, Movies, Video Games, and Podcasts to Check Out After Watching ‘A Knight of the Seven Kingdoms'
Protection

The Best Books, Movies, Video Games, and Podcasts to Check Out After Watching ‘A Knight of the Seven Kingdoms’

April 22, 2026
How to Spot AI Audiobooks on Libby
Protection

How to Spot AI Audiobooks on Libby

April 21, 2026
The Best Last-Minute Deals From Home Depot's 'Spring Black Friday' Sale
Protection

The Best Last-Minute Deals From Home Depot’s ‘Spring Black Friday’ Sale

April 21, 2026
10 Hacks Every Apple CarPlay User Should Know
Protection

10 Hacks Every Apple CarPlay User Should Know

April 21, 2026
The Samsung Galaxy Watch Ultra Is Over $100 Off Right Now
Protection

The Samsung Galaxy Watch Ultra Is Over $100 Off Right Now

April 21, 2026
11 of the Biggest Moments in Tim Cook's Time As Apple CEO
Protection

11 of the Biggest Moments in Tim Cook’s Time As Apple CEO

April 21, 2026
Load More
Next Post
Two-year UK mortgage rate rises above 6%

Two-year UK mortgage rate rises above 6%

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Chainalysis: Crypto Money Laundering Surged to $82 Billion in 2025

    0 shares
    Share 0 Tweet 0
  • Contrary To Popular Belief, This Is Not The Worst Bitcoin Crash In History – Here’s The List

    0 shares
    Share 0 Tweet 0
  • Blackstone launches first private multi-asset credit interval fund

    0 shares
    Share 0 Tweet 0
  • Explainer-How the State of the Union became a stage for political confrontation

    0 shares
    Share 0 Tweet 0

Latest News

crypto, South Korea, stablecoin, stablecoins

BOK New Governor Signals CBDC Push

April 22, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure The newly appointed Governor of the Bank...

Crypto Firms Report Flood of AI-Driven Bug Bounty Submissions

Crypto Firms Report Flood of AI-Driven Bug Bounty Submissions

April 22, 2026
0

Crypto protocols have warned that an increase in AI use has led to a flood of bogus bug bounty submissions,...

Watching People Watch Whales in Baja California's Sea of Cortez

Watching People Watch Whales in Baja California’s Sea of Cortez

April 22, 2026
0

The unhurried undulation of a whale’s movements is nearly inseparable from the rolling swells of the sea, making them easy...

Why these strategists say 45% of portfolios should be invested in gold, metals and bitcoin

Why these strategists say 45% of portfolios should be invested in gold, metals and bitcoin

April 22, 2026
0

Positive expectations from the Trump-Xi summit in Beijing mid-May may serve to underpin toppy equity markets in the near-term

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.