TF-MAL-osx.choziosi
📛 Threat Title
Malware family: Choziosi
Description
ThreatFox malware family `osx.choziosi`. Printable name: Choziosi. Aliases: ChromeLoader,Chropex.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.choziosi
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.choziosi
IOC database
- Type
- domain
- Value
osx.choziosi- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.choziosi
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.choziosi
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybergeeks.tech
Summary We analyzed a new version of ChromeLoader (also known as Choziosi Loader) that was seen in the wild in recent weeks. This ChromeLoader campaign that appears to have started in December 2021 has become widespread and has spawned multiple versions, making atomic indicators ineffective for detections. In our analysis we will be discussing the capabilities of this loader, as well as trying ...
-
web:hackread.com
ChromeLoader malware is spread through pirated games, malicious QR codes, and cracked software that hijacks the victim's web browser and inserts ads into webpages. Palo Alto Networks' Unit 42 researchers have uncovered new variants of the notorious ChromeLoader info-stealer malware , codenamed Choziosi Loader and ChromeBack.
-
web:malpedia.caad.fkie.fraunhofer.de
Choziosi 2022-05-25 ⋅ Red Canary ⋅ Aedan Russell ChromeLoader: a pushy malvertiser Choziosi Choziosi 2022-04-25 ⋅ th3protocol blog ⋅ Colin Cowie Choziosi Loader: Multi-platform campaign delivering browser extension malware Choziosi 2022-03-11 ⋅ Blackberry ⋅ BlackBerry Research & Intelligence Team
-
web:mirrors.gpmidi.net
Choziosi Loader: Multi-platform campaign delivering browser extension malware In Janurary 2022 a new malware campaign delivering chrome extensions was identified by @x3ph1. Orginally this malware was named ChromeLoader and CS_Installer due to observed scheduled task names and filename. In Feburary 2022 after some additonal activity GDATA named this malware family Choziosi Loader. Recently I ...
-
web:redcanary.com
ChromeLoader is a pervasive and persistent browser hijacker that modifies its victims' browser settings and redirects user traffic to advertisement websites. This malware is introduced via an ISO file that baits users into executing it by posing as a cracked video game or pirated movie or TV show. It eventually manifests as a browser extension. Like most suspicious browser extensions ...
-
web:redskyalliance.org
ChromeLoader proves to be an extremely prevalent and persistent malware . It initially drops as an .iso and can be used to leak users' browser credentials, harvest recent online activity, and hijack browser searches to display ads. The VMware Carbon Black Managed Detection and Response (MDR) team observed the first Windows variants of ChromeLoader in the wild in January 2022 and the macOS ...
-
web:thehackernews.com
A new ChromeLoader malware campaign is being distributed via virtual hard disk (VHD) files, marked as hacks or cracks for Nintendo and Steam games.
-
web:threatfox.abuse.ch
Indicators of Compromise (IOCs) on ThreatFox are associated with a certain malware fas. A malware sample can be associated with only one malware family . The page below gives you an overview on indicators of compromise associated with win. choziosi .
-
web:unit42.paloaltonetworks.com
Executive Summary In January 2022, a new browser hijacker/adware campaign named ChromeLoader (also known as Choziosi Loader and ChromeBack) was discovered. Despite using simple malicious advertisements, the malware became widespread, potentially leaking data from thousands of users and organizations. Instead of more traditional malware like a Windows executable (.exe) or Dynamic Link Library ...
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.