Advertisement
Canada markets close in 14 minutes
  • S&P/TSX

    21,967.09
    +81.71 (+0.37%)
     
  • S&P 500

    5,103.08
    +54.66 (+1.08%)
     
  • DOW

    38,254.56
    +168.76 (+0.44%)
     
  • CAD/USD

    0.7318
    -0.0005 (-0.07%)
     
  • CRUDE OIL

    83.66
    +0.09 (+0.11%)
     
  • Bitcoin CAD

    87,189.87
    -1,070.05 (-1.21%)
     
  • CMC Crypto 200

    1,331.25
    -65.29 (-4.67%)
     
  • GOLD FUTURES

    2,349.40
    +6.90 (+0.29%)
     
  • RUSSELL 2000

    2,001.96
    +20.85 (+1.05%)
     
  • 10-Yr Bond

    4.6690
    -0.0370 (-0.79%)
     
  • NASDAQ

    15,935.03
    +323.27 (+2.07%)
     
  • VOLATILITY

    14.94
    -0.43 (-2.80%)
     
  • FTSE

    8,139.83
    +60.97 (+0.75%)
     
  • NIKKEI 225

    37,934.76
    +306.28 (+0.81%)
     
  • CAD/EUR

    0.6838
    +0.0017 (+0.25%)
     

Fake Font Malware Is Affecting Google Chrome Windows Users

A new piece of malware called 'Font Wasn't Found' attempts to fool users into downloading it by appearing to be a missing font installation. The malware is been seen from Windows Google Chrome users.

Malware tends to use messages and false advertising to fool users into installing it and a new Chrome malware uses a unique workaround that you’ll want to keep an eye out for.

NeoSmart Technologies, via 9to5Google, discovered a malware prompt that appears on Google Chrome for Microsoft Windows users. As NeoSmart staffer Mahmoud Al-Qudsi writes, the malware works by replacing text on a page with gibberish and then prompting the user to download an update to the “Chrome Font Pack.”

“This attack gets a lot of things right that many others fail at. The premise is actually believable: the text doesn’t render, and it says that is caused by a missing font (HoeflerText, which is a real font, by the way!), which it then prompts you to download and install,” Al-Qudsi said. “The usage of a clean, well-formatted dialog to present the message with the correct Chrome logo – and, more importantly, – the correct shade of blue for the update button. The shape of the update button seems correct, and the spelling and grammar are definitely good enough to get a pass.”

Al-Qudsi notes the malware has several tells that indicate it’s a fake update. These include incorrect Chrome version descriptions and blurred image text. However, the biggest hurdle for the malware comes from how relatively new the program is. NeoSmart found that it wasn’t detected by Windows Defender or Chrome as being a malicious program.

ADVERTISEMENT

For users, general best practices for malware prevention will apply if you want to avoid a time-consuming cleaning process. When browsing the internet, stay alert for prompts that look unusual or out of place and avoid installing files that popups ask you to download.

Related Articles