{"id":1727,"date":"2023-10-25T14:27:06","date_gmt":"2023-10-25T19:27:06","guid":{"rendered":"https:\/\/wp.uthscsa.edu\/phishbowl\/?p=1727"},"modified":"2023-10-25T14:27:06","modified_gmt":"2023-10-25T19:27:06","slug":"the-fake-browser-update-scam","status":"publish","type":"post","link":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/1727\/","title":{"rendered":"The Fake Browser Update Scam"},"content":{"rendered":"<p>One of the oldest malware tricks in the book \u2014 hacked websites claiming visitors need to update their Web browser before they can view any content \u2014 has roared back to life in the past few months. New research shows the attackers behind one such scheme have developed an ingenious way of keeping their malware from being taken down by security experts or law enforcement: By hosting the malicious files on a decentralized, anonymous cryptocurrency blockchain.<\/p>\n<p>In August 2023, security researcher\u00a0Randy McEoin\u00a0blogged about a scam he dubbed\u00a0ClearFake, which uses hacked WordPress sites to serve visitors with a page that claims you need to update your browser before you can view the content.<\/p>\n<p>The fake browser alerts are specific to the browser you\u2019re using, so if you\u2019re surfing the Web with Chrome, for example, you\u2019ll get a Chrome update prompt. Those who are fooled into clicking the update button will have a malicious file dropped on their system that tries to install an information stealing trojan. This information comes from Krebs on Security.<\/p>\n<p>If you see a page similar one of the pictures below, close your browser. The site has probably been compromised because neither Chrome or Firefox deliver updates from websites.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1728\" src=\"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2023\/10\/20231025FakeUpdate.png\" alt=\"Screenshot of fake update page\" width=\"764\" height=\"491\" srcset=\"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2023\/10\/20231025FakeUpdate.png 764w, https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2023\/10\/20231025FakeUpdate-550x353.png 550w\" sizes=\"auto, (max-width: 764px) 100vw, 764px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1729\" src=\"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2023\/10\/20231025FakeUpdate2.png\" alt=\"Screenshot of fake update notice\" width=\"855\" height=\"568\" srcset=\"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2023\/10\/20231025FakeUpdate2.png 855w, https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2023\/10\/20231025FakeUpdate2-550x365.png 550w, https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2023\/10\/20231025FakeUpdate2-800x531.png 800w, https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2023\/10\/20231025FakeUpdate2-450x300.png 450w, https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2023\/10\/20231025FakeUpdate2-768x510.png 768w\" sizes=\"auto, (max-width: 855px) 100vw, 855px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>One of the oldest malware tricks in the book \u2014 hacked websites claiming visitors need to update their Web browser before they can view any content \u2014 has roared back to life in the past few months. New research shows the attackers behind one such scheme have developed an ingenious way of keeping their malware [&hellip;]<\/p>\n","protected":false},"author":412,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1727","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>The Fake Browser Update Scam - Phish Bowl<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/1727\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Fake Browser Update Scam - Phish Bowl\" \/>\n<meta property=\"og:description\" content=\"One of the oldest malware tricks in the book \u2014 hacked websites claiming visitors need to update their Web browser before they can view any content \u2014 has roared back to life in the past few months. New research shows the attackers behind one such scheme have developed an ingenious way of keeping their malware [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/1727\/\" \/>\n<meta property=\"og:site_name\" content=\"Phish Bowl\" \/>\n<meta property=\"article:published_time\" content=\"2023-10-25T19:27:06+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2023\/10\/20231025FakeUpdate.png\" \/>\n<meta name=\"author\" content=\"gerwitz\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"gerwitz\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/1727\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/1727\\\/\"},\"author\":{\"name\":\"gerwitz\",\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/#\\\/schema\\\/person\\\/2095530964cc8374433595be2eab7bde\"},\"headline\":\"The Fake Browser Update Scam\",\"datePublished\":\"2023-10-25T19:27:06+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/1727\\\/\"},\"wordCount\":209,\"image\":{\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/1727\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/wp-content\\\/uploads\\\/sites\\\/90\\\/2023\\\/10\\\/20231025FakeUpdate.png\",\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/1727\\\/\",\"url\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/1727\\\/\",\"name\":\"The Fake Browser Update Scam - Phish Bowl\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/1727\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/1727\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/wp-content\\\/uploads\\\/sites\\\/90\\\/2023\\\/10\\\/20231025FakeUpdate.png\",\"datePublished\":\"2023-10-25T19:27:06+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/#\\\/schema\\\/person\\\/2095530964cc8374433595be2eab7bde\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/1727\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/1727\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/1727\\\/#primaryimage\",\"url\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/wp-content\\\/uploads\\\/sites\\\/90\\\/2023\\\/10\\\/20231025FakeUpdate.png\",\"contentUrl\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/wp-content\\\/uploads\\\/sites\\\/90\\\/2023\\\/10\\\/20231025FakeUpdate.png\",\"width\":764,\"height\":491,\"caption\":\"Screenshot of fake update page\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/1727\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Fake Browser Update Scam\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/#website\",\"url\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/\",\"name\":\"Phish Bowl\",\"description\":\"Phish Bowl\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/#\\\/schema\\\/person\\\/2095530964cc8374433595be2eab7bde\",\"name\":\"gerwitz\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1e6628f5d379deb64268f4658e72b047dd7498c88eed2f376a82d36778aa1632?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1e6628f5d379deb64268f4658e72b047dd7498c88eed2f376a82d36778aa1632?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1e6628f5d379deb64268f4658e72b047dd7498c88eed2f376a82d36778aa1632?s=96&d=mm&r=g\",\"caption\":\"gerwitz\"},\"url\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/author\\\/gerwitz\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The Fake Browser Update Scam - Phish Bowl","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/1727\/","og_locale":"en_US","og_type":"article","og_title":"The Fake Browser Update Scam - Phish Bowl","og_description":"One of the oldest malware tricks in the book \u2014 hacked websites claiming visitors need to update their Web browser before they can view any content \u2014 has roared back to life in the past few months. New research shows the attackers behind one such scheme have developed an ingenious way of keeping their malware [&hellip;]","og_url":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/1727\/","og_site_name":"Phish Bowl","article_published_time":"2023-10-25T19:27:06+00:00","og_image":[{"url":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2023\/10\/20231025FakeUpdate.png","type":"","width":"","height":""}],"author":"gerwitz","twitter_card":"summary_large_image","twitter_misc":{"Written by":"gerwitz","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/1727\/#article","isPartOf":{"@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/1727\/"},"author":{"name":"gerwitz","@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/#\/schema\/person\/2095530964cc8374433595be2eab7bde"},"headline":"The Fake Browser Update Scam","datePublished":"2023-10-25T19:27:06+00:00","mainEntityOfPage":{"@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/1727\/"},"wordCount":209,"image":{"@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/1727\/#primaryimage"},"thumbnailUrl":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2023\/10\/20231025FakeUpdate.png","inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/1727\/","url":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/1727\/","name":"The Fake Browser Update Scam - Phish Bowl","isPartOf":{"@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/#website"},"primaryImageOfPage":{"@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/1727\/#primaryimage"},"image":{"@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/1727\/#primaryimage"},"thumbnailUrl":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2023\/10\/20231025FakeUpdate.png","datePublished":"2023-10-25T19:27:06+00:00","author":{"@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/#\/schema\/person\/2095530964cc8374433595be2eab7bde"},"breadcrumb":{"@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/1727\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/1727\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/1727\/#primaryimage","url":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2023\/10\/20231025FakeUpdate.png","contentUrl":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2023\/10\/20231025FakeUpdate.png","width":764,"height":491,"caption":"Screenshot of fake update page"},{"@type":"BreadcrumbList","@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/1727\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/wp.uthscsa.edu\/phishbowl\/"},{"@type":"ListItem","position":2,"name":"The Fake Browser Update Scam"}]},{"@type":"WebSite","@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/#website","url":"https:\/\/wp.uthscsa.edu\/phishbowl\/","name":"Phish Bowl","description":"Phish Bowl","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/wp.uthscsa.edu\/phishbowl\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/#\/schema\/person\/2095530964cc8374433595be2eab7bde","name":"gerwitz","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1e6628f5d379deb64268f4658e72b047dd7498c88eed2f376a82d36778aa1632?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1e6628f5d379deb64268f4658e72b047dd7498c88eed2f376a82d36778aa1632?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1e6628f5d379deb64268f4658e72b047dd7498c88eed2f376a82d36778aa1632?s=96&d=mm&r=g","caption":"gerwitz"},"url":"https:\/\/wp.uthscsa.edu\/phishbowl\/author\/gerwitz\/"}]}},"_links":{"self":[{"href":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-json\/wp\/v2\/posts\/1727","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-json\/wp\/v2\/users\/412"}],"replies":[{"embeddable":true,"href":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-json\/wp\/v2\/comments?post=1727"}],"version-history":[{"count":0,"href":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-json\/wp\/v2\/posts\/1727\/revisions"}],"wp:attachment":[{"href":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-json\/wp\/v2\/media?parent=1727"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-json\/wp\/v2\/categories?post=1727"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-json\/wp\/v2\/tags?post=1727"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}