Threat Database Trojans Trojan.Win32.Cromex.a

Trojan.Win32.Cromex.a

By JubileeX in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 16
First Seen: May 30, 2012
Last Seen: September 22, 2022
OS(es) Affected: Windows

Trojan.Win32.Cromex.a is disguised as a fake key generator for Steam (a popular online gaming network similar to iTunes). Computer users looking to access Steam illegally are lured into websites hosting Trojan.Win32.Cromex.a through a series of YouTube videos supposedly recommending this Key Generator. However, the supposed 'Key Generator' is an executable file that actually installs Trojan.Win32.Cromex.a on the victim's computer. This Trojan takes the form of a malicious extension for the Google Chrome web browser. Rather than enabling the computer user to access Steam without a legitimate key, Trojan.Win32.Cromex.a does the opposite, detecting whenever a computer user enters information related to online gaming accounts or sensitive information, such as email passwords or credit card numbers. Then, Trojan.Win32.Cromex.a relays this information to a remote server. Because of this, ESG malware analysts strongly advise against using these kinds of key generators as they are a prime form of malware distribution.

YouTube videos associated with Trojan.Win32.Cromex.a lead to three distinct websites, which are flashed as annotations on the YouTube clip associated with this threat. At these websites, computer users can download a file named 'steam Game Key Generator.exe'. There is a reason why most security researchers strongly recommend against downloading and running suspicious executable files; these are often disguised malware infections. This supposed key generator is no exception. Running it installs 7.0.1428.crx on the victim's computer system. This file is a Google Chrome extension hosted on the website theonlyone(dot)goodluckwith(dot)us. Then the computer user is prompted to authorize this Google Chrome extension, disguised as the popular web browser security plug-in associated with the Avast anti-virus.

This malicious Chrome plug-in contains two JavaScript files named background.js and webProtection.js. This second file will detect whenever any of the following strings are shown in the web page the victim is visiting:

accounts.google
darkorbit
dofus
gameforge
google
login.live
metin2
minecraft.net
remboursetonforfait
steamcommunity
steampowered

Once detected, Trojan.Win32.Cromex.a will log all keystrokes, mouse movements, and other activity in an effort to obtain the victim's passwords or other important information. Finally, this information is sent in the form of a cookie to a remote server associated with this threat. Trojan.Win32.Cromex.a has also been known to detect connections to YouTube and automatically pressing 'like' on the videos that are used to distribute this fake Steam key generator.

Trending

Most Viewed

Loading...