Don't fall for this Google Chrome email update scam

(Image credit: 19 Studio/Shutterstock)

The Google Chrome web browser sees regular updates every few weeks for both its desktop versions and its Android mobile app. 

So it's no shocker that you might be prompted to update your software to the latest version while browsing online. But it's important you know how to recognize a scam or a threat when you see it, particularly when it arrives via your workplace email account. 

In a blog post last week, researchers at security firm Proofpoint gave further news on an especially shady malware campaign that has been targeting educational institutions, governments and manufacturing companies for nearly a year. 

The latest wave of attacks involved 18,000 malicious emails sent in June and July to recipients in Canada, France, Germany, Italy, the U.K. and the U.S.

The emails prompt the recipient to visit a website of interest to persons in that chosen field. The site is legitimate, but it has been corrupted by an injection of the malicious JavaScript-based framework known as SocGholish, or TA569.

"Soc" standing for "social engineering," as the entire threat revolves around tricking victims into entering private information.

The SocGholish script first gleans information about your browser, operating system, and location. Then it decides whether to try to infect you with malware.

If so, then you are whisked to a second website, and this one really is fake — it's a fake browser update page that urges to click a button to download the "update". Proofpoint's examples including fake Google Chrome and Microsoft Internet Explorer updates, but this campaign also lures Mozilla Firefox users.

And of course, if you do click that button, then you're really downloading a script that further profiles your system and downloads more files, including the Chthonic banking Trojan and the legitimate but often-abused remote-access application NetSupport.

Like other banking Trojans, Chthonic tries to gain access to your online bank account in order to steal money. Meanwhile, NetSupport gives attackers remote control of your PC, potentially leading to full system takeover.

How to avoid this malware scam

If you want to make sure your version of Google Chrome is up to date without falling victim to malware, it's best to do so manually, as Google itself explains. 

Open your Chrome browser and take a look at the three dots on the top right of your window, the "More" icon. The icon may be green, orange or red, which means that an update is available. 

Green indicates that the update was released less than two days ago, while orange means it was released about four days ago. Red means the available update was released a week ago and you're overdue to install it. To update, click the three-dot icon and choose "Update Google Chrome." 

If you don't see "Update Google Chrome" at all, or the three-dot icon is gray, then it means you don't need to update and you're good to go. 

When the update is complete, you need to click "Relaunch" and your browser will close, then reopen automatically with the same tabs you had open. 

You can postpone this process by clicking "Not now," and the update will apply itself when you restart your browser. This way you're staying up to date and skipping out on scams. 

As for avoiding malware injections of this nature, the safest thing you can do is to not click on links within emails, especially those from unsolicited senders. 

You can also hover your mouse over a weblink before you click on it to see if the destination URL is fishy or not. (In this campaign, it might not be, since the crooks behind it seem to be corrupting legitimate websites without the knowledge of the sites' administrators.)

As a backup, making sure to have one of the best antivirus programs installed. It can root out malware you may have downloaded with an ill-advised click.

Brittany Vincent

Brittany Vincent has been covering video games and tech for over 13 years for publications including Tom's Guide, MTV, Rolling Stone, CNN, Popular Science, Playboy, IGN, GamesRadar, Polygon, Kotaku, Maxim, and more. She's also appeared as a panelist at video game conventions like PAX East and PAX West and has coordinated social media for companies like CNET. When she's not writing or gaming, she's looking for the next great visual novel in the vein of Saya no Uta. You can follow her on Twitter @MolotovCupcake.

Latest in Browsers
iPhone 16 Pro Max shown in hand
Your iPhone has a custom voice command feature — here's how to use it
iPhone 16 Pro Max shown in hand
You can change your iPhone's default browser — here's how
Google Chrome on Android
How to stop your personal data from appearing in Google searches
Opera Air
I just tested the world’s first mindful browser — it’s calmly convinced me to ditch Google Chrome
A photo of the Google Chrome logo on a white background, displayed on the screen of a large MacBook Pro which is situated on a table with green foliage behind.
Google Chrome just got three new modes — and it's a game changer for performance
Google Calendar app on iPhone
Google Calendar just got the dark mode we’ve been waiting for — here’s how to activate it
Latest in News
NYTimes Connections
NYT Connections today hints and answers — Tuesday, March 25 (#653)
A first look at Amazon's Fallout TV series coming to Prime Video
‘Fallout’ season 3 plans are reportedly being made — while season 2 is still filming
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on
New emojis with iOS 18.4 beta release.
iOS 18.4 beta brings 8 new emoji to your iPhone — here's all the new options
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
half-life alyx
Latest Half-Life 3 rumors point to a 2025 release — and maybe pigs will fly