TF-MAL-js.chromeback
📛 Threat Title
Malware family: ChromeBack
Description
ThreatFox malware family `js.chromeback`. Printable name: ChromeBack.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
js.chromeback
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.chromeback
IOC database
- Type
- domain
- Value
js.chromeback- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-js.chromeback
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.chromeback
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (9)
-
web:consumer.ftc.gov
Malware is one of the biggest threats to the security of your computer, tablet, phone, and other devices. Learn how to protect yourself, how to tell if your device has malware , and how to remove it.
-
web:malpedia.caad.fkie.fraunhofer.de
GoSecure describes ChromeBack as a browser hijacker, redirecting traffic and serving advertisements to users.
-
web:unit42.paloaltonetworks.com
A malicious browser extension is the payload of the ChromeLoader malware family , serving as adware and an infostealer, leaking users' search queries.
-
web:www.breachsense.com
Malware incident response is the coordinated process of identifying, containing, eradicating, and recovering from malware infections. It includes isolating infected systems, analyzing the malware's behavior, remediating affected accounts, and implementing controls to prevent reinfection.
-
web:www.certkiller.com
CVE-2025-6554's inclusion establishes a compliance deadline of July 23, 2025, requiring agencies to complete vulnerability remediation or implement alternative risk mitigation measures before this date.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.microsoft.com
A developer-targeting campaign leveraged malicious Next.js repositories to trigger a covert RCE-to-C2 chain through standard build workflows. The activity demonstrates how staged command-and-control can hide inside routine development tasks.
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
-
web:www.wiz.io
Understand the critical aspects of CVE-2025-2783 with a detailed vulnerability assessment, exploitation potential, affected technologies, and remediation guidance.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.