Fake Google Chrome Extension Downloaded by Over 200,000 Users

Share post:

Researchers have discovered a Google Chrome extension called Internet Download Manager, which is an adware and has been downloaded by more than 200,000 users.

Although the extension installs a well-known and legitimate download manager program, researchers were able to show some irregular behaviors through the extension. These irregular behaviors include opening links to spammy sites, changing the default browser search engine, and more display pop-ups asking users to download more “patches” and unwanted programs.

After installing the fake ‘Internet Download Manager,’ users are prompted to install an executable program from the Puupnewsapp website and to download a “Windows patch” ZIP file.

Further investigation reveals that there is a legitimate Windows program called Internet Download Manager from software company Tonec. Tonec offers Internet Download Manager extensions for Firefox and Chrome, and the authentic Chrome extension that the company provides is called the “IDM Integration Module.”

However, the fake ‘Internet Download Manager’ Chrome extension is maintained by a website called “Puupnewsapp,” which claims that “it increases your download speed by up to 500%,” making it a “super software” that is used to download games, movies, music and “large files in minutes.”

The sources for this piece include an article in BleepingComputer.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways