EXECUTIVE SUMMARY
A recent malvertising campaign targeting users seeking to download the Arc web browser for Windows has raised significant cybersecurity concerns. The Arc browser, known for its innovative user interface, garnered attention with its Windows launch following successful debuts on macOS. However, cybercriminals exploited this anticipation by setting up malicious advertisements on Google Search, directing unsuspecting users to typo-squatted domains resembling the legitimate Arc website.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A recent malvertising campaign targeting users seeking to download the Arc web browser for Windows has raised significant cybersecurity concerns. The Arc browser, known for its innovative user interface, garnered attention with its Windows launch following successful debuts on macOS. However, cybercriminals exploited this anticipation by setting up malicious advertisements on Google Search, directing unsuspecting users to typo-squatted domains resembling the legitimate Arc website.[emaillocker id="1283"]
Technically, the campaign leverages Google search ads that appear legitimate, complete with the Arc browser's official logo and website. When users search for terms like "arc installer" or "arc browser windows," they encounter these deceptive ads. Clicking on these ads leads users to malicious websites where they download an installer named "ArcBrowser.exe." This installer contains two executables: one installs the genuine Arc browser, while the other operates covertly. The malware communicates with the MEGA cloud platform via its API, using disposable email addresses for authentication. Subsequent stages involve downloading further payloads from sites, which hide malicious code within PNG images. The malware then executes these codes, often using legitimate system processes like MSBuild.exe to avoid detection, and eventually connects to command and control servers to exfiltrate user data.
This incident underscores the importance of vigilance when interacting with sponsored search results. Cybercriminals can create highly convincing ads and installers that bypass traditional security measures. Users are advised to be cautious and verify the legitimacy of download sources, especially for newly released software. Endpoint Detection and Response (EDR) systems can be crucial in identifying and mitigating such threats by recognizing suspicious activity patterns. As cyber threats evolve, so must our awareness and defenses to protect against increasingly sophisticated social engineering attacks.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| T1189 | Drive-by Compromise | |
| Execution | T1059 | Command and Scripting Interpreter |
| T1053 | Scheduled Task/Job | |
| Defense Evasion | T1218 | System Binary Proxy Execution |
| T1036 | Masquerading | |
| T1027 | Obfuscated Files or Information | |
| Credential Access | T1552 | Unsecured Credentials |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]