HPQ HP Inc.

ChromeLoader malware campaign punishes pirating users, HP warns

ChromeLoader malware campaign punishes pirating users, HP warns

New report finds attackers hiding malware in OneNote documents, while threat actors use trusted domains to bypass Office macro controls

PALO ALTO, Calif., June 14, 2023 (GLOBE NEWSWIRE) -- HP Inc. (NYSE: HPQ) today issued its quarterly , showing threat actors are hijacking users’ Chrome browsers if they try to download popular movies or video games from pirating websites.

By isolating threats that have evaded detection tools on PCs, HP Wolf Security has specific1 insight into the latest techniques being used by cybercriminals in the fast-changing cybercrime landscape. To date, HP Wolf Security customers have clicked on over 30 billion email attachments, web pages, and downloaded files with no reported breaches.

Based on data from millions of endpoints running HP Wolf Security2, the researchers found:

  • is hard to wash out: A campaign distributing the ChromeLoader malware tricks users into installing a malicious Chrome extension called Shampoo. It can redirect the victim’s search queries to malicious websites, or pages that will earn the criminal group money through ad campaigns. The malware is highly persistent, using Task Scheduler to re-launch itself every 50 minutes.
  • Attackers bypass macro policies by using trusted domains: While macros from untrusted sources are now disabled, HP saw attackers bypass these controls by compromising a trusted Office 365 account, setting up a new company email, and distributing a malicious excel file that infects victims with the Formbook infostealer.
  • Firms must beware of what lurks beneath: OneNote documents can act as digital scrapbooks, so any file can be attached within. Attackers are taking advantage of this to embed malicious files behind fake “click here” icons. Clicking the fake icon opens the hidden file, executing malware to give attackers access to the users’ machine – this access can then be sold on to other cybercriminal groups and ransomware gangs.

Sophisticated groups like Qakbot and IcedID first embedded malware into OneNote files in January. With OneNote kits now available on cybercrime marketplaces and requiring little technical skill to use, their malware campaigns look set to continue over the coming months.

“To protect against the latest threats, we advise that users and businesses avoid downloading materials from untrusted sites, particularly pirating sites. Employees should be wary of suspicious internal documents and check with the sender before opening. Organizations should also configure email gateway and security tool policies to block OneNote files from unknown external sources,” explains Patrick Schläpfer, Malware Analyst at the HP Wolf Security threat research team, HP Inc.

From malicious archive files to HTML smuggling, the report also shows cybercrime groups continue to diversify attack methods to bypass email gateways, as threat actors move away from Office formats. Key findings include:

  • Archives were the most popular malware delivery type (42%) for the fourth quarter running when examining threats stopped by HP Wolf Security in Q1.
  • There was a 37-percentage-point rise in HTML smuggling threats in Q1 versus Q4.
  • There was a 4-point rise in PDF threats in Q1 versus Q4.
  • There was a 6-point drop in Excel malware (19% to 13%) in Q1 versus Q4, as the format has become more difficult to run macros in.
  • 14% of email threats identified by HP Sure Click bypassed one or more email gateway scanner in Q1 2023.
  • The top threat vector in Q1 was email (80%) followed by browser downloads (13%).

“To protect against increasingly varied attacks, organizations must follow zero trust principles to isolate and contain risky activities such as opening email attachments, clicking on links, or browser downloads. This greatly reduces the attack surface along with the risk of a breach,” comments Dr. Ian Pratt, Global Head of Security for Personal Systems, HP Inc.

HP Wolf Security runs risky tasks like opening email attachments, downloading files and clicking links in isolated, micro-virtual machines (micro-VMs) to protect users. It also captures detailed traces of attempted infections. HP’s application isolation technology mitigates threats that might slip past other security tools and provides unique insights into novel intrusion techniques and threat actor behavior.

About the data

This data was anonymously gathered within HP Wolf Security customer virtual machines from January-March 2023.

About HP

HP Inc. (NYSE: HPQ) is a global technology leader and creator of solutions that enable people to bring their ideas to life and connect to the things that matter most. Operating in more than 170 countries, HP delivers a wide range of innovative and sustainable devices, services and subscriptions for personal computing, printing, 3D printing, hybrid work, gaming, and more. For more information, please visit: .

About HP Wolf Security

HP Wolf Security is a new breed of endpoint security. HP’s portfolio of hardware-enforced security and endpoint-focused security services are designed to help organizations safeguard PCs, printers, and people from circling cyber predators. HP Wolf Security provides comprehensive endpoint protection and resiliency that starts at the hardware level and extends across software and services. Visit .

Media Contact

Vanessa Godsal, HP Media Relations


1 HP has specific insight into the latest cybercriminal techniques because it analyses real world malware samples in micro-virtual machines (micro-VMs), capturing detailed traces of attempted infections.

2 HP Security is now HP Wolf Security. Security features vary by platform, please see product data sheet for details.

 



EN
14/06/2023

Underlying

To request access to management, click here to engage with our
partner Phoenix-IR's CorporateAccessNetwork.com

Reports on HP Inc.

 PRESS RELEASE

HP Inc. Reports Fiscal 2025 Full Year and Fourth Quarter Results

HP Inc. Reports Fiscal 2025 Full Year and Fourth Quarter Results PALO ALTO, Calif., Nov. 25, 2025 (GLOBE NEWSWIRE) -- HP (NYSE: HPQ) Fiscal 2025 GAAP diluted net earnings per share ("EPS") of $2.65, down 5.7% from the prior year periodFiscal 2025 non-GAAP diluted net EPS of $3.12, down 9.0% from the prior year periodFiscal 2025 net revenue of $55.3 billion, up 3.2% from the prior-year periodFiscal 2025 net cash provided by operating activities of $3.7 billion, free cash flow of $2.9 billionFiscal 2025 returned $1.9 billion to shareholders in the form of dividend and share repurchasesFour...

 PRESS RELEASE

HP Inc. to Announce Fourth Quarter Fiscal 2025 Earnings on Nov 25, 202...

HP Inc. to Announce Fourth Quarter Fiscal 2025 Earnings on Nov 25, 2025 PALO ALTO, Calif., Nov. 04, 2025 (GLOBE NEWSWIRE) -- HP Inc. (NYSE: HPQ) will present a live audio webcast of a conference call to review financial results for the fourth fiscal quarter and fiscal year ended October 31, 2025 on Tuesday, Nov 25, 2025 at 5:00 p.m. ET / 2:00 p.m. PT. The webcast will be available at .  A replay of the audio webcast will be available at the same website shortly after the call and will remain available for approximately one year. About HP Inc. HP Inc. (NYSE: HPQ) is a global technology...

 PRESS RELEASE

New OMEN Gear Delivers Tournament-Ready Performance with Fan-Inspired ...

New OMEN Gear Delivers Tournament-Ready Performance with Fan-Inspired Design HP expands its Riot Games lineup with the OMEN 16 League of Legends Limited Edition Laptop and OMEN 25 Gaming Monitor, built for fans and pros alike News Highlights: Introduces the OMEN 16 League of Legends Limited Edition Laptop, featuring game-inspired aesthetics, upgraded thermal design, and intelligent performance optimization with OMEN AIDebuts the OMEN 25 Gaming Monitor, the official display of League of Legends Esports and the VALORANT Champions Tour, delivering 360 Hz1 visuals and 1 ms1 response for comp...

 PRESS RELEASE

HP Accelerates the Future of Work

HP Accelerates the Future of Work Company transforms future-ready workspaces and simplifies work experiences with intelligent AI-powered solutions News Highlights:  Announces 14 innovations to enhance workspaces, AI workflows, remote device support, and smart printing experiences.Introduces new ways to curate and maximize workspace with the latest displays and a dock that features proximity activation.Innovates AI development with the HP ZGX Nano G1n AI Station and new HP ZGX Toolkit.Empowers IT with new features, like Remote Connect, to securely access employee devices, perform live tro...

HP Inc: 1 director

A director at HP Inc sold 34,282 shares at 26.850USD and the significance rating of the trade was 68/100. Is that information sufficient for you to make an investment decision? This report gives details of those trades and adds context and analysis to them such that you can judge whether these trading decisions are ones worth following. Included in the report is a detailed share price chart which plots discretionary trades by all the company's directors over the last two years clearly showing ...

ResearchPool Subscriptions

Get the most out of your insights

Get in touch