Nowadays, people pay more and more attention to network security, and they are more vigilant about security awareness than before. For the general public who are becoming more and more savvy, malicious people have begun to come up with new tricks, and even take advantage of everyone’s savvy to do some harmful things. Google recently disclosed a scam method that pretends to be the Brave browser website. This is not new. What’s even better is that it also advertises in Google search results, making everyone mistakenly believe that it is the real official website.

Malware pretends to be the Brave browser to deceive clicks and downloads, and even buys ads on Google to look like the real thing.
The method of fraud discovered this time can be said to be a perfect copy of the Brave browser website. It uses a very similar “Bravė” as the beginning of the website address, and the other suffixes are exactly the same as the real official website. Due to the screen size limiting the font size, it is difficult to see at a glance that there is an extra dot above the e. You might even mistake it for a dirty thing stuck on it. After clicking into the website, if you click the download button, it does not bring the installation program of the Brave browser, but malware files named ArechClient and SectopRat.

Most of the fraud methods we often see are secretive and low-key. This malicious website is obviously quite high-profile. In order to drive traffic to fake websites, unscrupulous people also buy ads on Google. When people search for browser-related keywords, these ads will be displayed on the search results page. The description of the ad looks very good and good (as shown below), but the name of the function variable displayed on the ad is mckelveytees.com, a website that sells clothing for professionals.


But when someone clicks on one of the ads, it leads through several intermediate domains until you reach the final destination – the Bravė fake official website. A virus was detected in the malicious files provided on the fake website. This virus has multiple names, including ArechClient, SectopRat, etc. This Trojan was discovered in 2019 and is used as a remote attack to stream the user’s current desktop or create a second invisible desktop. After follow-up tracking in February, the security company G Data found that the liver malware had been updated and added new functions, including attacker control commands and encrypted communication to control the server. Another analysis showed that it has the ability to connect to C2 servers, analyze systems, and steal browsing history records from browsers.

Google has now removed these malicious ads, and NameCheap has taken down the malicious domain name after being notified. The saying “The devil is in the details” is also very applicable to cyber attacks. These deceptions hidden in various details are very difficult to detect. Since the attacker has complete control of the Punycode domain name, the fake website will have a valid TLS certificate. When the domain name hosts an exact copy of the scam website, even security-conscious people can be easily fooled. Unfortunately, there is no clear way to avoid these security threats other than taking a few extra seconds to check the URL in the address bar, and there are likely to be imitators of similar scams, so be careful.
◎Data source:ArsTechnica
Source: KOCPC Chinese