ChromeLoader malware spread through malvertising tied to torrents and cracked software, using ISO files on Windows and DMG files on macOS to lure users into installing multi-stage droppers. Rather than deploying a conventional payload, the campaign installed malicious browser extensions that hijacked search activity, opened advertisements, and exfiltrated queries from search engines including Google, Yahoo, and Bing to attacker-controlled infrastructure.
Researchers linked the activity to a rapidly evolving malware family also tracked as Choziosi Loader and ChromeBack, with variants observed across Windows and macOS. The malware used scheduled tasks, registry Run keys, PowerShell, batch files, bash scripts, and heavily obfuscated JavaScript to establish persistence and complicate analysis, showing a cross-platform adware and infostealer operation designed to resist removal and maintain long-term browser access.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Variant 2 emerged in March 2022 and used ISO images with hidden files and LNK shortcuts, then batch scripts and PowerShell to establish persistence and install extension version 6.0.
A macOS ChromeLoader variant emerged in March 2022, using DMG files and bash scripts to install malicious extensions targeting Google Chrome and Safari.
ChromeLoader Variant 1 was first seen in January 2022, using a .NET dropper, malicious ISO images, scheduled-task persistence, and extension versions 2.0 through 4.4.
ChromeLoader, also known as Choziosi Loader and ChromeBack, was discovered in January 2022 as a browser hijacker and adware campaign spread through malicious browser extensions.
An earlier ChromeLoader Windows variant, identified as Variant 0, was active in December 2021 and used AutoHotKey-compiled executables with malicious browser extension version 1.0.
A newer in-the-wild ChromeLoader version was analyzed using heavily obfuscated PowerShell to fetch and execute a C# stager that installed a malicious browser extension from AppData. The variant targeted Chromium-based browsers, included nonfunctional Firefox code paths, redirected Google searches through attacker-controlled infrastructure to Bing, and used encrypted QUIC communications plus new indicators such as Withyourrety[.]xyz.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 314 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
cybergeeks.tech
Open sourceunit42.paloaltonetworks.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.