Malware

New browser malware uses remote commands to control Windows systems

According to Cyber Insider, security researchers at Intezer have discovered a sophisticated browser application capable of remotely injecting keyboard and mouse commands into Windows systems, posing a significant threat to user security. This malicious operation has been active for at least 10 years.

The malware, disguised as a "privacy browser," was distributed via a deceptive sponsored search result after an employee mistyped a URL. The application, built with NW.js, includes a hidden input-injection engine that allows attackers to execute commands remotely, mimicking a USB Rubber Ducky. This engine can launch applications, generate synthetic mouse and keyboard activity, modify default search engines, and install browser extensions. To evade detection, the malware waits for periods of inactivity and hides browser windows during its operations.

Systems in multiple countries, including the United States, Canada, and various European nations, have been targeted with varying levels of malicious activity. The attackers utilized the MSIX installer format to appear more legitimate, leveraging Microsoft's App Installer. However, inadvertently captured registry data exposed developer artifacts, linking this campaign to previous NW.js-based attacks dating back to 2016.

Source: Cyber Insider

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds