s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.choziosi

📛 Threat Title

Malware family: Choziosi

Category: Choziosi First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.choziosi`. Printable name: Choziosi. Aliases: ChromeLoader,Chropex.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.choziosi VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.choziosi

IOC database

Type
domain
Value
osx.choziosi
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.choziosi

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.choziosi

References (1)

Remediations (10)

  • web:cybergeeks.tech

    Summary We analyzed a new version of ChromeLoader (also known as Choziosi Loader) that was seen in the wild in recent weeks. This ChromeLoader campaign that appears to have started in December 2021 has become widespread and has spawned multiple versions, making atomic indicators ineffective for detections. In our analysis we will be discussing the capabilities of this loader, as well as trying ...

  • web:hackread.com

    ChromeLoader malware is spread through pirated games, malicious QR codes, and cracked software that hijacks the victim's web browser and inserts ads into webpages. Palo Alto Networks' Unit 42 researchers have uncovered new variants of the notorious ChromeLoader info-stealer malware , codenamed Choziosi Loader and ChromeBack.

  • web:malpedia.caad.fkie.fraunhofer.de

    Choziosi 2022-05-25 ⋅ Red Canary ⋅ Aedan Russell ChromeLoader: a pushy malvertiser Choziosi Choziosi 2022-04-25 ⋅ th3protocol blog ⋅ Colin Cowie Choziosi Loader: Multi-platform campaign delivering browser extension malware Choziosi 2022-03-11 ⋅ Blackberry ⋅ BlackBerry Research & Intelligence Team

  • web:mirrors.gpmidi.net

    Choziosi Loader: Multi-platform campaign delivering browser extension malware In Janurary 2022 a new malware campaign delivering chrome extensions was identified by @x3ph1. Orginally this malware was named ChromeLoader and CS_Installer due to observed scheduled task names and filename. In Feburary 2022 after some additonal activity GDATA named this malware family Choziosi Loader. Recently I ...

  • web:redcanary.com

    ChromeLoader is a pervasive and persistent browser hijacker that modifies its victims' browser settings and redirects user traffic to advertisement websites. This malware is introduced via an ISO file that baits users into executing it by posing as a cracked video game or pirated movie or TV show. It eventually manifests as a browser extension. Like most suspicious browser extensions ...

  • web:redskyalliance.org

    ChromeLoader proves to be an extremely prevalent and persistent malware . It initially drops as an .iso and can be used to leak users' browser credentials, harvest recent online activity, and hijack browser searches to display ads. The VMware Carbon Black Managed Detection and Response (MDR) team observed the first Windows variants of ChromeLoader in the wild in January 2022 and the macOS ...

  • web:thehackernews.com

    A new ChromeLoader malware campaign is being distributed via virtual hard disk (VHD) files, marked as hacks or cracks for Nintendo and Steam games.

  • web:threatfox.abuse.ch

    Indicators of Compromise (IOCs) on ThreatFox are associated with a certain malware fas. A malware sample can be associated with only one malware family . The page below gives you an overview on indicators of compromise associated with win. choziosi .

  • web:unit42.paloaltonetworks.com

    Executive Summary In January 2022, a new browser hijacker/adware campaign named ChromeLoader (also known as Choziosi Loader and ChromeBack) was discovered. Despite using simple malicious advertisements, the malware became widespread, potentially leaking data from thousands of users and organizations. Instead of more traditional malware like a Windows executable (.exe) or Dynamic Link Library ...

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.