Office of Information Technology
May 9, 2023
Tags Phishing Email (in the wild)

Phony Google Chrome updates

Phish Bowl Alerts

A warning for users of the Google Chrome browser of malware being distributed in phony updates for it. According to Trend Micro, visiting a legitimate but compromised website infected with the malicious code will prompt a fake Google Chrome error message.

Trend Micro reports that "When you visit these websites, a fake Google Chrome error message will prompt you to download an update to fix a supposed security issue. What you’re really downloading is a ZIP file that has an EXE file inside. This EXE file contains a Monero miner that will use your computer’s processing power to mine cryptocurrency for the attackers."

Protection tips include exercising caution when downloading anything from unknown sources (limit software downloads to only trusted websites) and keeping your operating system, software and web browser up-to-date. For Google Chrome users, use the built-in update feature by clicking Help and selecting About Chrome. 

Read the full story and see a screenshot of an example on Trend Micro's site.