Thousands Of Chrome Browsers At Risk Of Free Software Scams
Date: May 15, 2025
An ongoing trojan malware campaign has been caught by researchers infecting thousands of Google Chrome and Microsoft Edge browsers.
Cybersecurity researchers have found an ongoing trojan malware campaign that is hijacking web browsers to steal confidential information. This sophisticated campaign targets Google Chrome and Microsoft Edge browsers masked as free popular software like Roblox FPS Unlocker, VLC media player, KeePass, Steam, and YouTube.
The single malicious campaign has hit over 300,000 Google Chrome and Microsoft Edge users globally. The victims fell for the impressively lookalike websites of mainstream tech giants like YouTube to install trojan malware that has been around since 2021. This malware has the power to take over control of the installation and task execution of multiple browser extensions and add-ons.
"The trojan malware contains different deliverables ranging from simple adware extensions that hijack searches to more sophisticated malicious scripts that deliver local extensions to steal private data and execute various commands"
- Spokesperson (ReasonLabs research team)
The malware also changes the default search engine to the user's preferred one, which keeps bouncing back even when users change it back to their original one. These search engines serve as a convenient playground for running ads or deploying more dangerous malware. Earlier, this malware was hidden in cracked versions of paid softwares that many websites offered for free.
The most dangerous part about these malware is that they cannot be removed from the system without a tough fight. Major antivirus software leaves the malware unnoticed or cannot be removed from the system, even though it has existed for over three years by now. The extensions enabled by the malware cannot be disabled even in Developer mode. Newer versions of the malware have scripts that can easily remove browser updates that identify or delete the extensions.
One way to remove this malware from browsers is to eliminate it from the system folders themselves. This effort includes deleting scheduled tasks that reactivate the malware and removing registry entries and their associated files and folders as named below:
- C:\Windows\system32\Privacyblockerwindows.ps1
- C:\Windows\system32\Windowsupdater1.ps1
- C:\Windows\system32\WindowsUpdater1Script.ps1
- C:\Windows\system32\Optimizerwindows.ps1
- C:\Windows\system32\Printworkflowservice.ps1
- C:\Windows\system32\NvWinSearchOptimizer.ps1 - 2024 version
- C:\Windows\system32\kondserp_optimizer.ps1 - May 2024 version
- C:\Windows\InternalKernelGrid
- C:\Windows\InternalKernelGrid3
- C:\Windows\InternalKernelGrid4
- C:\Windows\ShellServiceLog
- C:\windows\privacyprotectorlog
- C:\Windows\NvOptimizerLog
Users who find these folders in their system can also check if their sensitive data was pawned online. To safeguard themselves against monetary losses, these systems must remove all confidential data, including passwords, financial credentials, and other personal documents.
By Arpit Dubey
Arpit is a dreamer, wanderer, and tech nerd who loves to jot down tech musings and updates. With a knack for crafting compelling narratives, Arpit has a sharp specialization in everything: from Predictive Analytics to Game Development, along with artificial intelligence (AI), Cloud Computing, IoT, and let’s not forget SaaS, healthcare, and more. Arpit crafts content that’s as strategic as it is compelling. With a Logician's mind, he is always chasing sunrises and tech advancements while secretly preparing for the robot uprising.
// Recommended
Pinterest Follows Amazon in Layoffs Trend, Shares Fall by 9%
AI-driven restructuring fuels Pinterest layoffs, mirroring Amazon’s strategy, as investors react sharply and question short-term growth and advertising momentum.
Clawdbot Rebrands to "Moltbot" After Anthropic Trademark Pressure: The Viral AI Agent That’s Selling Mac Minis
Clawdbot is now Moltbot. The open-source AI agent was renamed after Anthropic cited trademark concerns regarding its similarity to their Claude models.
Amazon Bungles 'Project Dawn' Layoff Launch With Premature Internal Email Leak
"Project Dawn" leaks trigger widespread panic as an accidental email leaves thousands of Amazon employees bracing for a corporate cull.
OpenAI Launches Prism, an AI-Native Workspace to Shake Up Scientific Research
Prism transforms the scientific workflow by automating LaTeX, citing literature, and turning raw research into publication-ready papers with GPT-5.2 precision.
Have newsworthy information in tech we can share with our community?
