According to Cyber Insider, security researchers at Intezer have discovered a sophisticated browser application capable of remotely injecting keyboard and mouse commands into Windows systems, posing a significant threat to user security. This malicious operation has been active for at least 10 years.The malware, disguised as a "privacy browser," was distributed via a deceptive sponsored search result after an employee mistyped a URL. The application, built with NW.js, includes a hidden input-injection engine that allows attackers to execute commands remotely, mimicking a USB Rubber Ducky. This engine can launch applications, generate synthetic mouse and keyboard activity, modify default search engines, and install browser extensions. To evade detection, the malware waits for periods of inactivity and hides browser windows during its operations.Systems in multiple countries, including the United States, Canada, and various European nations, have been targeted with varying levels of malicious activity. The attackers utilized the MSIX installer format to appear more legitimate, leveraging Microsoft's App Installer. However, inadvertently captured registry data exposed developer artifacts, linking this campaign to previous NW.js-based attacks dating back to 2016.Source: Cyber Insider
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
Related Terms
AdwareYou can skip this ad in 5 seconds
