The Financial News 247The Financial News 247
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
What's On
How Black Women Influencers Dominated A B Market At Essence Fest

How Black Women Influencers Dominated A $24B Market At Essence Fest

July 9, 2025
Pacers Sign Rookie Kam Jones To Unique Four-Year Standard Contract

Pacers Sign Rookie Kam Jones To Unique Four-Year Standard Contract

July 9, 2025
T-Mobile scraps DEI programs while seeking crucial FCC approval for major business deals

T-Mobile scraps DEI programs while seeking crucial FCC approval for major business deals

July 9, 2025
5 Simple but Tough-to-Answer Client Questions

5 Simple but Tough-to-Answer Client Questions

July 9, 2025
To See The Next Total Solar Eclipse, Book Now — Here’s Why

To See The Next Total Solar Eclipse, Book Now — Here’s Why

July 9, 2025
Facebook X (Twitter) Instagram
The Financial News 247The Financial News 247
Demo
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
The Financial News 247The Financial News 247
Home » Warning—Do Not Install This Google Chrome Update

Warning—Do Not Install This Google Chrome Update

By News RoomApril 11, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Telegram Reddit Email Tumblr
Warning—Do Not Install This Google Chrome Update
Share
Facebook Twitter LinkedIn Pinterest Email

With Google warning that Chrome is under attack, it is not surprising that its 3 billion users are primed to keep their browsers updated. But be warned — sometimes the update can be more dangerous than the vulnerabilities it’s meant to fix.

So it is with a new report from DomainTools, warning that “deceptive websites hosted on newly registered domains are being used to deliver AndroidOS SpyNote malware. These sites mimic the Google Chrome install page on the Google Play Store to lure victims into downloading SpyNote, a potent Android remote access trojan (RAT).”

We have been here before. Google Chrome has proven a particularly enticing honeypot for cybercriminals looking to trick Android users into downloading malware. Users are frequently told only to install and update apps from Play Store, and so it’s especially concerning that the new websites mimic Play Store’s own Chrome page.

As the cybersecurity team at Cyfirma explain, “SpyNote first emerged in 2020. Since its inception, it has become one of the most prevalent malware families targeting Android devices… Researchers have identified over 10,000 samples of SpyNote.”

Masquerading as fake updates and installs is the common way in which SpyNote tricks its way onto phones. Once there, it can be used for “surveillance, data exfiltration, and remote control.” It can also be primed to search for digital wallets to steal crypto, as well as targeting valuable financial security credentials.

The new websites “include an image carousel displaying screenshots of mimicked Google Play app pages. These images are loaded from “bafanglaicai888[.]top.” another suspicious domain suspected to be owned by the same actor. The carousel provides a visual aspect to enhance the illusion of a legitimate app page.”

The attacks are likely developed in China and exploit Chinese top-level domains. DomainTools warns that on installation, SpyNote “aggressively requests numerous intrusive permissions, gaining extensive control over the compromised device. This control allows for the theft of sensitive data such as SMS messages, contacts, call logs, location information, and files. SpyNote also boasts significant remote access capabilities, including camera and microphone activation and call manipulation.”

SpyNote can also steal two-factor authentication (2FA) codes, remotely wipe a phone and pull additional malware onto the device. It is, the researchers say, “a significant threat to individuals and organizations targeted by these deceptive campaigns.”

The URLs tagged in the latest campaign are as follows:

  • pknby[.]top
  • jygst[.]top
  • dacmj[.]top
  • mkstq[.]top
  • sakiw[.]top
  • fdtya[.]top
  • hgcks[.]top
  • npkms[.]top
  • kmyjh[.]top
  • kyudfsaugsda[.]top
  • bafanglaicai888[.]top

Those in the U.S. might be familiar with the .TOP domain as it’s used heavily in the plague of road toll smishing scams now targeting iPhone and Android users.

The Anti-Phishing Working Group (APWG) warns China’s .TOP domain “has a notable history of being used by phishers.” This has resulted in the .TOP Registry’s long-running compliance problems. ICANN issued a breach letter to .TOP Registry in July 2024, citing .TOP’s failures to comply with abuse reporting and mitigation requirements, and as of March 2025 the case is still listed as unresolved on ICANN’s Web site.”

Advice for users is simple — whether on Android or any other device. Only ever update Chrome from within the app or from the official app store you use. Access that store directly and never through a link in an email, message or post.

Android Attack Android malware android warning Chrome Attack chrome warning chrome zero day google warning pixel warning samsung warning
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related News

How Black Women Influencers Dominated A B Market At Essence Fest

How Black Women Influencers Dominated A $24B Market At Essence Fest

July 9, 2025
To See The Next Total Solar Eclipse, Book Now — Here’s Why

To See The Next Total Solar Eclipse, Book Now — Here’s Why

July 9, 2025
Danone’s Academy Wants To Train 20,000 AI-Ready Workers

Danone’s Academy Wants To Train 20,000 AI-Ready Workers

July 9, 2025
3 Reasons Why ‘Constructive Complaining’ Is Good For You, By A Psychologist

3 Reasons Why ‘Constructive Complaining’ Is Good For You, By A Psychologist

July 9, 2025
Intangible Launches Public Beta, Merging Generative AI, Game Engines, And Cinematic Design

Intangible Launches Public Beta, Merging Generative AI, Game Engines, And Cinematic Design

July 9, 2025
AI Startup LangChain Is In Talks To Raise 0 Million

AI Startup LangChain Is In Talks To Raise $100 Million

July 9, 2025
Add A Comment

Leave A Reply Cancel Reply

Don't Miss
Pacers Sign Rookie Kam Jones To Unique Four-Year Standard Contract

Pacers Sign Rookie Kam Jones To Unique Four-Year Standard Contract

News July 9, 2025

INDIANAPOLIS – Kam Jones has signed his first professional contract, inking a four-year deal with…

T-Mobile scraps DEI programs while seeking crucial FCC approval for major business deals

T-Mobile scraps DEI programs while seeking crucial FCC approval for major business deals

July 9, 2025
5 Simple but Tough-to-Answer Client Questions

5 Simple but Tough-to-Answer Client Questions

July 9, 2025
To See The Next Total Solar Eclipse, Book Now — Here’s Why

To See The Next Total Solar Eclipse, Book Now — Here’s Why

July 9, 2025
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks
‘M3GAN 2.0’ Star On Reuniting With Killer AI-Powered Doll

‘M3GAN 2.0’ Star On Reuniting With Killer AI-Powered Doll

July 9, 2025
Former Hasbro CEO Alan Hassenfeld, whose family founded iconic toy maker, dead at 76

Former Hasbro CEO Alan Hassenfeld, whose family founded iconic toy maker, dead at 76

July 9, 2025
Danone’s Academy Wants To Train 20,000 AI-Ready Workers

Danone’s Academy Wants To Train 20,000 AI-Ready Workers

July 9, 2025
Here’s how the new Trump accounts work — and why financial experts don’t love them

Here’s how the new Trump accounts work — and why financial experts don’t love them

July 9, 2025
The Financial News 247
Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us
© 2025 The Financial 247. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.