英语阅读 学英语,练听力,上听力课堂! 注册 登录
> 轻松阅读 > 双语阅读 >  内容

谷歌浏览器被曝含恶意插件

所属教程:双语阅读

浏览:

2018年05月15日

手机版
扫描二维码方便学习和分享
Researchers with cybersecurity firm Trend Microhave uncovered a malicious extension inGoogle's Chrome web browser that uses a multitudeof methods to steal and mine cryptocurrency frominfected users.

近日,网络安全公司趋势科技的研究人员在谷歌Chrome浏览器中发现了一个恶意扩展程序,它会使用多种方法从受感染的用户那里窃取和挖掘加密货币。

The malware, which Trend Micro calls "FacexWorm", makes its way onto a victim's browser via socialengineering tactics conducted through FacebookMessenger.

趋势科技将该恶意软件称为“FacexWorm”,它是通过Facebook Messenger进行的社交工程策略侵入受害者的浏览器。

A target would receive a link leading to a fake YouTube page that would prompt the user toinstall an extension in order to play the video. Once the extension is installed, it'sprogrammed to hijack users' Facebook accounts and spread the link throughout their friendslist.

一个目标会收到一个链接,弹出一个虚假的YouTube页面,提示用户安装扩展程序以播放视频。一旦安装了扩展程序,它就会被编程为劫持用户的Facebook账号并将其链接传播到他们的朋友列表中。

FacexWorm appears to be a Swiss Army knife of cryptocurrency-oriented malware. According toTrend Micro, the malicious extension has various capabilities:

FacexWorm似乎是面向加密货币恶意软件的“瑞士军刀”。据趋势科技称,恶意扩展具有各种功能:

If an infected user tries logs into Google, MyMonero or Coinhive, FacexWorm will intercept thecredentials.

如果受感染用户尝试登录谷歌、MyMonero或Coinhive,FacexWorm将拦截凭证。

When a victim tries to go to a specified set of cryptocurrency trading platforms, they getredirected to a scam site that requests a small amount of Ether, ostensibly for verificationpurposes.

当受害者试图访问一组指定的加密货币交易平台时,他们会被重定向到一个要求少量Ether的骗局网站,表面上用于验证目的。

If FacexWorm detects that a user is on a cryptocurrency transaction page, the extensionreplaces the wallet address entered by the user with another one from the attacker.

如果FacexWorm检测到用户处于加密货币交易页面,则扩展程序将用户输入的钱包地址替换为攻击者的另一个地址。

Trend Micro says currencies targeted include bitcoin, Bitcoin Gold, Bitcoin Cash, Dash, Ethereum, Ethereum Classic, Ripple, Litecoin, Zcash and Monero.

趋势科技表示,目标货币包括比特币、比特币黄金、比特币现金、Dash、以太币、Ethereum Classic、瑞波币、莱特币、Zcash和Monero。

谷歌浏览器被曝含恶意插件 会盗取用户虚拟货币?

Trying to go to certain websites will redirect a victim to a referral link that rewards theattacker.

试图访问某些网站会将受害者重定向到奖励攻击者的推荐链接。

And, of course, FacexWorm has a cryptojacking component, using the victim's processor tomine for cryptocurrency.

当然,FacexWorm还有一个加密组件,使用受害者的处理器来挖掘加密货币。

If an affected user appears to be trying to remove the malicious plugin, it has ways ofstopping them, Trend Micro says. If a user tries opening Chrome's extension managementpage, the malware will simply close the tab.

趋势科技称,如果受影响的用户似乎试图删除恶意插件,它还有方式进行阻止。如果用户尝试打开Chrome的扩展管理页面,恶意软件将简单关闭该选项卡。

FacexWorm reportedly first surfaced last year. But it appears to be adware-oriented in its firstiteration and hasn't been very active until Trend Micro noticed it last month.

据报道,FacexWorm去年首次出现。但它在第一次迭代中似乎是面向广告软件的,并且在趋势科技上个月发现它之前一直非常活跃。

Trend Micro says it's only discovered one instance in which FacexWorm compromised a bitcointransaction, according to the attacker's digital wallet address, but that that there's no wayto tell for sure how much the attackers have actually profited.

根据攻击者的数字钱包地址,只有FacexWorm发现了一个比特币交易被入侵的例子,但是没有办法确定攻击者实际获利的多少。

The attacker is persistently trying to upload more FacexWorm-infected extensions to theChrome Web Store, the researchers say, but Google is proactively removing them.

研究人员说,攻击者一直在试图将更多受FacexWorm感染的扩展程序上传到Chrome网上应用店,但Google正在主动将其删除。

Trend Micro says Facebook, with which it has a partnership, has automated measures thatdetect the bad links and block their spread.

趋势科技称Facebook与其建立了合作伙伴关系,已经采用自动化措施来检测不良链接并阻止其传播。
 


用户搜索

疯狂英语 英语语法 新概念英语 走遍美国 四级听力 英语音标 英语入门 发音 美语 四级 新东方 七年级 赖世雄 zero是什么意思日照市华润置地广场(山东东路)英语学习交流群

网站推荐

英语翻译英语应急口语8000句听歌学英语英语学习方法

  • 频道推荐
  • |
  • 全站推荐
  • 推荐下载
  • 网站推荐