{"id":11918,"date":"2018-04-03T08:10:07","date_gmt":"2018-04-03T16:10:07","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2018\/04\/03\/news-5687\/"},"modified":"2018-04-03T08:10:07","modified_gmt":"2018-04-03T16:10:07","slug":"news-5687","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/04\/03\/news-5687\/","title":{"rendered":"Malicious gaming extensions: a child&#8217;s play to infection"},"content":{"rendered":"<p><strong>Credit to Author: Pieter Arntz| Date: Tue, 03 Apr 2018 15:30:00 +0000<\/strong><\/p>\n<p>Did you ever lend your laptop to a child to play a video game, only to get it back filled with advertisements? <a href=\"https:\/\/lifehacker.com\/im-marcin-kleczynski-and-this-is-the-story-behind-malw-1766148437\" target=\"_blank\" rel=\"noopener\">Our CEO knows<\/a>\u00a0a little bit about that predicament, having unknowingly infected his parents&#8217; computer when he was a kid. But times have changed since then.<\/p>\n<p>Let us play for you a modern-day scenario, then, to show how it&#8217;s a short trip from \u201cI want to play this game\u201d to \u201cHey, there\u2019s adware on my laptop!\u201d<\/p>\n<h3>How to get infected playing a video game<\/h3>\n<p>These days the coolest kids at school aren&#8217;t playing football\u2014they&#8217;re playing video games. Of course, your kid wants to be the best in a popular game like Slither.io. So he grabs the family laptop and does a search for \u201c<a href=\"https:\/\/www.google.com\/search?q=always+win+slither&amp;oq=always+win+slither&amp;aqs=chrome..69i57.3714j0j8&amp;sourceid=chrome&amp;ie=UTF-8\" target=\"_blank\" rel=\"noopener\">always win slither<\/a>.\u201d<\/p>\n<p>Look at the top search result: a <a href=\"https:\/\/www.youtube.com\/watch?v=3MXgn10-Qfs\" data-rel=\"lightbox-video-0\" target=\"_blank\" rel=\"noopener\">YouTube video<\/a> by a well-known YouTuber named Jelly, who has 7,866,496 subscribers tuning into his gaming channel. If you were a gaming portal, would you think it&#8217;s worth the investment to pay <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2015\/06\/adchoices-interest-based-advertising\/\" target=\"_blank\" rel=\"noopener\">AdChoices<\/a> to get a relevant advertisement on that page?<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/YouTubeAdvertisementw.png\" data-rel=\"lightbox-0\" title=\"\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"22789\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/malicious-gaming-extensions-a-childs-play-to-infection\/attachment\/youtubeadvertisementw\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/YouTubeAdvertisementw.png\" data-orig-size=\"1336,702\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"YouTubeAdvertisementw\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/YouTubeAdvertisementw-300x158.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/YouTubeAdvertisementw-600x315.png\" class=\"wp-image-22789 size-large aligncenter\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/YouTubeAdvertisementw-600x315.png\" alt=\"slither.io youtube video\" width=\"600\" height=\"315\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/YouTubeAdvertisementw-600x315.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/YouTubeAdvertisementw-300x158.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/YouTubeAdvertisementw-630x330.png 630w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/YouTubeAdvertisementw.png 1336w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p style=\"text-align: center\"><em>Well-placed advertising always pays off.<\/em><\/p>\n<p>With its prominence and high potential for pay-off, the answer is decidedly &#8220;yes,&#8221; especially if your intentions are less than ethical. Normally, the game is free to play, but who is going to stop you from creating a landing page that says you have to install this browser extension before you can play?<\/p>\n<p>Advertising networks certainly won&#8217;t.\u00a0In order to advertise online, businesses must merely sign up with a network and then bid in real time to have their ads appear on popular websites. However, not all advertising networks have strict criteria for advertisers\u2014ad sellers don\u2019t always know the buyers. Not only that, but buying advertising space is increasingly being transacted automatically, which leaves the door open for further mischief.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/landingw.png\" data-rel=\"lightbox-1\" title=\"\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"22790\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/malicious-gaming-extensions-a-childs-play-to-infection\/attachment\/landingw\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/landingw.png\" data-orig-size=\"802,537\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"landingw\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/landingw-300x201.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/landingw-600x402.png\" class=\"wp-image-22790 size-large aligncenter\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/landingw-600x402.png\" alt=\"install extension\" width=\"600\" height=\"402\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/landingw-600x402.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/landingw-300x201.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/landingw.png 802w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p style=\"text-align: center\"><em>Install the extension, even though the game is completely free, why don\u2019t you?<\/em><\/p>\n<p>So, back to our kid. Remember, he just learned how to beat all his friends, so he&#8217;s eager to get going. He downloads the extension at the upper right-hand side of the screen because it&#8217;s the closest thing resembling a &#8220;play&#8221; button. What harm is a little extension going to do?<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"22791\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/malicious-gaming-extensions-a-childs-play-to-infection\/attachment\/wasrning1w\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/wasrning1w.png\" data-orig-size=\"398,169\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"wasrning1w\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/wasrning1w-300x127.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/wasrning1w.png\" class=\"aligncenter wp-image-22791 size-full\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/wasrning1w.png\" alt=\"permissions\" width=\"398\" height=\"169\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/wasrning1w.png 398w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/wasrning1w-300x127.png 300w\" sizes=\"auto, (max-width: 398px) 100vw, 398px\" \/><\/p>\n<p>All it can do is \u201cRead and change all your data on the websites you visit,\u201d after all.<\/p>\n<p>Wait, what?<\/p>\n<p>Yes, it knows which websites you visit, gathering all the data about your surfing behavior. And yes, it can use that information to insert relevant advertisements on those sites. And unfortunately, that\u2019s exactly what these extensions do. So we have a question for your kid, who&#8217;s about to install this extension on your laptop:<\/p>\n<blockquote>\n<p>Do you treat advertisements on the site of your favorite gaming portal with the same level of trust as the ones on a random Facebook page? Or do you trust one site&#8217;s ads over the other?<\/p>\n<\/blockquote>\n<p>If the answer isn&#8217;t clear here, then we might need to supply further instruction on the psychology behind successful marketing: The power to insert advertisements on sites that your target audience trusts is a desirable one\u2014one that cybercriminals would gladly pay for.<\/p>\n<p>And pay they did, aiming their advertising campaigns at games that attract a relatively young audience, including Slither.io, HappyWheels, Paper.io, Subway Surfers, MineCraft, and BlockWorld, among others.<\/p>\n<h3>What does the malicious browser extension actually do?<\/h3>\n<p>Now that the line of infection is clear, let\u2019s talk numbers.<\/p>\n<p>Because their advertising landing pages are so prominent and well-placed, gaming extensions bring in a lot of traffic to Chrome&#8217;s Webstore. The GamerSuperstar extension, for example, has been installed almost 100,000 times.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/webstorew.png\" data-rel=\"lightbox-2\" title=\"\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"22792\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/malicious-gaming-extensions-a-childs-play-to-infection\/attachment\/webstorew\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/webstorew.png\" data-orig-size=\"800,497\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"webstorew\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/webstorew-300x186.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/webstorew-600x373.png\" class=\"aligncenter wp-image-22792 size-large\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/webstorew-600x373.png\" alt=\"extension in webstore\" width=\"600\" height=\"373\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/webstorew-600x373.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/webstorew-300x186.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/webstorew.png 800w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p>If you download the extension directly from Webstore, you probably have a better idea of what its capabilities and permissions are by scrolling through the product descriptions and reading user reviews. This is not true, however, if you just click prompts from an advertising landing page. And that&#8217;s how these criminals pull the wool over users&#8217; eyes, getting thousands to download without realizing what they are getting into.<\/p>\n<p>And what they&#8217;re getting into is a whole lotta adware.<\/p>\n<p>The extension does absolutely nothing to change the gameplay\u2014it&#8217;s completely unnecessary. All you gain by installing most of these extensions is targeted advertising on the sites you visit. A select few also alter your search and newtab settings.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"22860\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/malicious-gaming-extensions-a-childs-play-to-infection\/attachment\/newtabw\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/newtabw.png\" data-orig-size=\"725,460\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"newtabw\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/newtabw-300x190.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/newtabw-600x381.png\" class=\"wp-image-22860 size-large aligncenter\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/newtabw-600x381.png\" alt=\"ArcadeTab newtab\" width=\"600\" height=\"381\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/newtabw-600x381.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/newtabw-300x190.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/newtabw.png 725w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p style=\"text-align: center\"><em>ArcadeTab comes with a search newtab<\/em><\/p>\n<h3>Other malicious gaming extensions<\/h3>\n<p>I wish we could say that GamerSuperStar was the only example of a malicious gaming extension that we have come across. Over the last few months, however, we&#8217;ve tracked quite a few of them.<\/p>\n<ul>\n<li><strong>Search Web<\/strong> by arcadetab.com: 1 million+ installs (and this one also qualifies as a search and newtab hijacker)<\/li>\n<li><strong>ArcadeFrontier Ads<\/strong> by arcadefrontier.com: 150,000+ installs<\/li>\n<li><strong>GamesChill Ads<\/strong> by gameschill.com: 100,000+ installs<\/li>\n<li><strong>PlayZiz Advertisements<\/strong> by playziz.com: 40,000+ installs<\/li>\n<li><strong>Gamerscan Ad<\/strong> by gamerscan.com: 25,000+ installs<\/li>\n<li><strong>ArcadeGala Advertising Offers<\/strong> by arcadegala.com: 5,000+ installs<\/li>\n<li><strong>VideoGameHub Advertising<\/strong> by videogaminghub.com: 1,500+ installs<\/li>\n<\/ul>\n<p>One note about the above: Data for Chrome extensions are a lot easier to track down because of their Webstore listing. We know there are Firefox and Safari extensions as well, but we can only guess at the numbers for Firefox and Safari extensions that were installed.<\/p>\n<p>So these other extensions\u2014no way they could be more aggressive on permissions than GamerSuperStar, right? Wrong. It was among the least demanding extension of its kind.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"22794\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/malicious-gaming-extensions-a-childs-play-to-infection\/attachment\/permissionsw-2\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/permissionsw.png\" data-orig-size=\"490,343\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"permissionsw\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/permissionsw-300x210.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/permissionsw.png\" class=\"wp-image-22794 size-full aligncenter\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/permissionsw.png\" alt=\"Gamerscan Ad permissions\" width=\"490\" height=\"343\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/permissionsw.png 490w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/permissionsw-300x210.png 300w\" sizes=\"auto, (max-width: 490px) 100vw, 490px\" \/><\/p>\n<p style=\"text-align: center\"><em>This was the most demanding extension permissions list we saw.<\/em><\/p>\n<h3>Remediating the infection<\/h3>\n<p>Although thousands of people were fooled into downloading these data-gathering extensions, it&#8217;s easy enough to get rid of them. If\u00a0you look at the uninstall page for GamerSuperStar on Chrome, you can see there are removal instructions for Firefox and Safari extensions as well.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/uninstallw.png\" data-rel=\"lightbox-3\" title=\"\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"22793\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/malicious-gaming-extensions-a-childs-play-to-infection\/attachment\/uninstallw\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/uninstallw.png\" data-orig-size=\"940,125\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"uninstallw\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/uninstallw-300x40.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/uninstallw-600x80.png\" class=\"aligncenter wp-image-22793 size-large\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/uninstallw-600x80.png\" alt=\"more browser extensions\" width=\"600\" height=\"80\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/uninstallw-600x80.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/uninstallw-300x40.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/uninstallw.png 940w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p>In addition,\u00a0<a href=\"https:\/\/www.malwarebytes.com\" target=\"_blank\" rel=\"noopener\">Malwarebytes<\/a> can block many of these kinds of extensions from being downloaded in the first place, since they fetch their advertisements from the cmptch.com servers, which have been at the top of our block list consistently for the last few weeks.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"22795\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/malicious-gaming-extensions-a-childs-play-to-infection\/attachment\/protection2-34\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/protection2.png\" data-orig-size=\"472,304\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"protection2\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/protection2-300x193.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/protection2.png\" class=\"wp-image-22795 size-full aligncenter\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/protection2.png\" alt=\"block cmptch.com\" width=\"472\" height=\"304\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/protection2.png 472w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/protection2-300x193.png 300w\" sizes=\"auto, (max-width: 472px) 100vw, 472px\" \/><\/p>\n<p style=\"text-align: center\"><em>The paid version of Malwarebytes blocks the domain cmptch.com.<\/em><\/p>\n<p>Malwarebytes also detects the extensions involved. Most of them are under the generic detection name Adware.Cmptch.Generic. You can find a\u00a0<a href=\"https:\/\/forums.malwarebytes.com\/topic\/225378-removal-instructions-for-gamersuperstar\/\" target=\"_blank\" rel=\"noopener\">removal guide for GamerSuperstar<\/a>\u00a0and a <a href=\"https:\/\/forums.malwarebytes.com\/topic\/225514-removal-instructions-for-arcadetab\/\" target=\"_blank\" rel=\"noopener\">ArcadeTab<\/a> on our forums.<\/p>\n<h3>Caught red-handed<\/h3>\n<p>The common pattern that we found for all these extensions is that they advertise their gaming portal heavily, and when clicking on the ads to arrive at the portal, you will instead be prompted to install an extension before you can play. If you visit the portal directly, however, you can jump straight in and start playing without being bothered.<\/p>\n<p>Even though it\u2019s hard to prove that these extensions are all coming from the same source, the similarities between the ways in which they are pushed and their target audience make us believe that they are at least closely-related. We also found similar domains and extensions acting suspiciously, but since we didn\u2019t catch them in the act, we will not list them here.<\/p>\n<p>But rest assured&#8230;we&#8217;re keeping an eye on them.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"22796\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/malicious-gaming-extensions-a-childs-play-to-infection\/attachment\/arcadeextensions\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/arcadeextensions.gif\" data-orig-size=\"567,301\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"arcadeextensions\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/arcadeextensions-300x159.gif\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/arcadeextensions.gif\" class=\"aligncenter wp-image-22796 size-full\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/arcadeextensions.gif\" alt=\"redhanded\" width=\"567\" height=\"301\" \/><\/p>\n<h3>IOCs<\/h3>\n<p>Chrome extensions:<\/p>\n<pre>obpnlclobfjomjabiibfnbfmebenjedp  peglehonblabfemopkgmfcpofbchegcl  dehhfjanlmglmabomenmpjnnopigplae  anaojjlbaalfefdgonnpmcpgpeafkdig  eogmpgppidehapppmipeahegomlindkg  piblbljcjideclibhpjobcaakomfcdnf  kfljkfcdekakneakneabhomcpmgfpbdc  flpdiedhjcapelfbeffompkoeilgmkhm  <\/pre>\n<p>Firefox extension:<\/p>\n<pre>{70cfab72-ee99-428a-b5fb-26d924be3acb}.xpi  <\/pre>\n<p>Domains:<\/p>\n<pre>cmptch.com  arcadetab.com  arcadefrontier.com  gameschill.com  playziz.com  gamerscan.com  arcadegala.com  videogaminghub.com  <\/pre>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/malicious-gaming-extensions-a-childs-play-to-infection\/\">Malicious gaming extensions: a child&#8217;s play to infection<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/malicious-gaming-extensions-a-childs-play-to-infection\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Pieter Arntz| Date: Tue, 03 Apr 2018 15:30:00 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/malicious-gaming-extensions-a-childs-play-to-infection\/' title='Malicious gaming extensions: a child's play to infection'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/03\/Childsplay.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>Some gaming portals have been preying on children to get their malicious extensions installed. They use targeted advertizing and offer (already) free games as a reward for installing their adware.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/social-engineering-cybercrime\/\" rel=\"category tag\">Social engineering<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/adware\/\" rel=\"tag\">adware<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/cmptch\/\" rel=\"tag\">cmptch<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/extensions\/\" rel=\"tag\">extensions<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/gaming\/\" rel=\"tag\">gaming<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/malicious-gaming-extensions\/\" rel=\"tag\">malicious gaming extensions<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/slither\/\" rel=\"tag\">slither<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/video-games\/\" rel=\"tag\">video games<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/webstore\/\" rel=\"tag\">webstore<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/malicious-gaming-extensions-a-childs-play-to-infection\/' title='Malicious gaming extensions: a child's play to infection'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/malicious-gaming-extensions-a-childs-play-to-infection\/\">Malicious gaming extensions: a child&#8217;s play to infection<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10468,18001,4503,11058,1445,18002,18003,10510,4433,18004],"class_list":["post-11918","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-adware","tag-cmptch","tag-cybercrime","tag-extensions","tag-gaming","tag-malicious-gaming-extensions","tag-slither","tag-social-engineering","tag-video-games","tag-webstore"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/11918","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=11918"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/11918\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=11918"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=11918"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=11918"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}