Chrome, beware of extensions: they may contain malware

The malware mainly affects users of illegal streaming platforms, installing on Google's browser a malicious extension

Discovered a new malware that spreads through Chrome. Its name is Submelius and it was discovered by ESET, a well-known company specialized in computer security. The malicious code, once it manages to trick victims, installs itself as a Chrome extension and directs users to malicious content.

Submelius, according to what ESET experts claim, mainly strikes on illegal streaming platforms. The virus follows a precise strategy that includes several steps. First, it appears in the form of an advertisement, one of those that says "earn money working from home" or "a virus has been detected". Next, if the victim falls for the hacker's trap and clicks on the banner, he is directed to a web page that prompts the user to open another website. As a final step, the malware asks the unfortunate person to press "Accept". And this is where Submelius enters its most important phase: the malware, in fact, ends up installing a malicious extension on Chrome.

How the malware affects you

Once the malicious extension is installed, the security of Chrome, and also of the machine used by the victim, is irreparably compromised. The malware, in fact, can freely modify the web pages visited by the affected user, direct his web traffic to dangerous sites that contain advertisements and, even worse, other malware. What is more, while browsing, Submelius will show victims information about their system.

The malware, which chose Chrome to target, conducted its malicious campaign between April and May, hitting first Latin American countries and then Europe as well, especially Spain and Italy, and managed to infect 45% of users.

How to protect yourself

First of all, avoid clicking on misleading advertisements. It is always good to check the installed extensions. To do this, simply go to your browser's settings and from the "Other Tools" item press on "Extensions". At this point, all you have to do is delete all the extensions that seem dangerous to you.