Fake Google Chrome Website Tricks Users into Installing Malware


Google Chrome is the most widely used web browser in the world, and this dominance makes it a great vector for cybercriminals to use to spread malware to unsuspecting users.

The SonicWall Capture Labs threat research team recently found what appears to be a legitimate website where a user can download and install Google Chrome. But the website is a fake – it installs malicious files that have nothing to do with Google Chrome. Upon clicking on the download button, an archive file named “Goegle sretp.zip” is downloaded. Within this zip file is an executable with the same name.

Read more…
Source: SonicWall


Sign up for our Newsletter


Related:

  • Shai-Hulud worm makes jump to AI infrastructure with Tensorlake compromise

    October 8, 2026

    The credential-hijacking Shai-Hulud worm has struck again, this time burrowing its way into a popular AI agent platform SDK. Multiple security researchers reported Thursday that they had detected Shai-Hulud infection in a recent release of the npm package for version 0.5.144 of Tensorlake’s SDK. That package has somewhere in the neighborhood of 12,000 downloads per week, ...

  • Attackers uses poem to infect thousands of servers with malware

    October 8, 2026

    Somewhere in the trackless wastes of cyberspace, a digital Robert Langdon is decoding an ancient poem to find the location of his masters and receive instructions on his next steps. I might be exaggerating a bit, but this is the gist of a rather bizarre story on cyberattacks and cryptocurrency mining. Cybersecurity researchers from Lumen’s Black ...

  • Attackers hijack country-code domains to impersonate Google and other services

    October 8, 2026

    According to Google, attackers compromised infrastructure behind three country-code domain namespaces—.gh (Ghana), .sl (Sierra Leone), and .as (American Samoa)—and used it to obtain unauthorized HTTPS certificates for Google domains and other organizations. These domain endings aren’t limited to sites serving those countries, so the risk can extend to users elsewhere. This wasn’t a break in encryption, ...

  • Update Chrome and ChromeOS to fix critical security issues

    October 7, 2026

    Google has released updates for the Chrome browser and the ChromeOS operating system. On October 6, Google released a Stable Channel Update for Desktop. This is the most important one for desktop users. It brings Chrome to version 155.0.8059.39 for Linux and versions 154.0.8037.39/.40 for Windows and Mac. The update includes 247 security fixes including four rated Critical. On the same ...

  • Blinder Tunnel Campaign Targets Iraqi Infrastructure

    October 6, 2026

    Palo Alto Unit 42 discovered that an Iranian state-aligned threat actor has been masquerading as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. Unit 42 tracks the activity as CL-STA-1178. This activity includes a campaign they call “Blinder Tunnel,” that targeted Iraqi critical infrastructure in March 2026, following infrastructure staging ...

  • Hackers access data of 8.8 million people in Denmark in ‘extremely serious’ breach

    October 5, 2026

    A major cybersecurity breach has exposed the personal data of 8.8 million people in Denmark. Denmark has suffered a major data breach after hackers broke into the country’s national population registry and accessed the personal information of millions of people. The country’s digital affairs minister announced the data breach on Monday, calling it “an extremely serious incident” ...