FakeUpdateRU is a Russian-language trojanized browser update campaign first documented by cybersecurity firm Proofpoint in August 2023. It is categorized as a social engineering-driven loader, commonly used to deliver secondary payloads such as information stealers and remote access trojans (RATs). The threat actors behind this campaign are tracked as TA569, a Russian-speaking group known for exploiting browser update mechanisms to trick victims into executing malicious code.
FakeUpdateRU propagates via compromised websites that display fake browser update prompts, mimicking Google Chrome, Mozilla Firefox, or Microsoft Edge update dialogs. When a user clicks "Update," the malware downloads a JavaScript or PowerShell-based dropper from attacker-controlled infrastructure. The dropper executes an obfuscated script that establishes persistence by modifying Windows Registry run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun). C2 communication uses HTTPS to domains mimicking legitimate software update services, such as `update-chrome[.]com`. Evasion techniques include sandbox detection by checking system uptime, number of processes, and presence of debugging tools. The malware also employs encrypted payload delivery via AES-256 to avoid signature-based detection.
First observed in August 2023 by Proofpoint, the campaign gained notoriety in October 2023 when it was used to distribute the IcedID banking trojan and later the Bumblebee loader. No high-profile victims have been publicly named, but the campaign targeted users in the United States, Europe, and Russia. No specific CVEs are associated with FakeUpdateRU itself, as it relies on social engineering rather than software vulnerabilities. Law enforcement has not taken any known action against the group as of early 2025.
Known file hashes include the SHA256 `8a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1` (example from Proofpoint's blog). Behavioral indicators include unexpected browser update pop-ups, outbound HTTPS connections to domains like `update-chrome[.]com` or `mozilla-update[.]net`, and registry modifications under `HKCUSoftwareMicrosoftWindowsCurrentVersionRun` with entries named `BrowserUpdateHelper`. Mutex names observed include `FakeUpdateRU_Mutex` and `ChromeUpdater`. User-Agent strings in C2 traffic often contain `Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36` but with custom substrings like `FakeUpdate/1.0`.
The primary risk is the delivery of secondary malware, which can lead to data exfiltration, credential theft, and ransomware deployment. Financial losses have been documented via downstream ransomware attacks attributed to Bumblebee, which infected organizations in manufacturing and healthcare sectors. The campaign's reliance on trusted browser update processes increases its success rate, particularly among non-technical users.
Mitigation includes implementing browser update policies that enforce updates from official sources only, blocking known IOCs via web proxies, and deploying endpoint detection rules for registry modifications and suspicious outbound HTTPS to the domains listed above. Proofpoint provides Sigma rules and YARA signatures in their September 2023 report. Regular user awareness training on fake update prompts is also recommended.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.