HP Ireland has issued its quarterly HP Wolf Security Threat Insights Report, showing threat actors are hijacking users’ Chrome browsers if they try to download popular movies or video games from pirating websites.

By isolating threats that have evaded detection tools on PCs, HP Wolf Security has specific insight into the latest techniques being used by cybercriminals in the fast-changing cybercrime landscape. To date, HP Wolf Security customers have clicked on over 30 billion email attachments, web pages, and downloaded files with no reported breaches.

Based on data from millions of endpoints running HP Wolf Security, the researchers found:

  • The Shampoo Chrome extension is hard to wash out: A campaign distributing the ChromeLoader malware tricks users into installing a malicious Chrome extension called Shampoo. It can redirect the victim’s search queries to malicious websites, or pages that will earn the criminal group money through ad campaigns. The malware is highly persistent, using Task Scheduler to re-launch itself every 50 minutes.
  • Attackers bypass macro policies by using trusted domains: While macros from untrusted sources are now disabled, HP saw attackers bypass these controls by compromising a trusted Office 365 account, setting up a new company email, and distributing a malicious excel file that infects victims with the Formbook infostealer.
  • Firms must beware of what lurks beneath: OneNote documents can act as digital scrapbooks, so any file can be attached within. Attackers are taking advantage of this to embed malicious files behind fake “click here” icons. Clicking the fake icon opens the hidden file, executing malware to give attackers access to the users’ machine – this access can then be sold on to other cybercriminal groups and ransomware gangs.

Sophisticated groups like Qakbot and IcedID first embedded malware into OneNote files in January. With OneNote kits now available on cybercrime marketplaces and requiring little technical skill to use, their malware campaigns look set to continue over the coming months.

To limit the chances of a security breach, businesses and users should avoid downloading files from untrusted sites. We have observed that threat actors are hijacking users’ Chrome browsers at times when downloading popular movies or video games from pirating websites. To protect against the latest threats, employees should be cautious of suspicious internal documents and check with the sender before opening. Organisations should also configure email gateway and security tool policies to block OneNote files from unknown external sources,” explains Val Gabriel, Managing Director of HP Ireland.

From malicious archive files to HTML smuggling, the report also shows cybercrime groups continue to diversify attack methods to bypass email gateways, as threat actors move away from Office formats. Key findings include:

  • Archives were the most popular malware delivery type (42%) for the fourth quarter running when examining threats stopped by HP Wolf Security in Q1.
  • There was a 37-percentage-point rise in HTML smuggling threats in Q1 versus Q4.
  • There was a 4-point rise in PDF threats in Q1 versus Q4.
  • There was a 6-point drop in Excel malware (19% to 13%) in Q1 versus Q4, as the format has become more difficult to run macros in.
  • 14% of email threats identified by HP Sure Click bypassed one or more email gateway scanner in Q1 2023.
  • The top threat vector in Q1 was email (80%) followed by browser downloads (13%).

To protect against increasingly varied attacks, organisations must follow zero trust principles to isolate and contain risky activities such as opening email attachments, clicking on links, or browser downloads. This greatly reduces the attack surface along with the risk of a breach,” comments Dr. Ian Pratt, Global Head of Security for Personal Systems, HP Inc.

HP Wolf Security runs risky tasks like opening email attachments, downloading files and clicking links in isolated, micro-virtual machines (micro-VMs) to protect users. It also captures detailed traces of attempted infections. HP’s application isolation technology mitigates threats that might slip past other security tools and provides unique insights into novel intrusion techniques and threat actor behavior.

See more stories here.

Ronan Leonard

Recent Posts

Transition Year Students and Women’s Collective Ireland Participants Graduate from Maynooth University STEM Inclusion Programme

Participants from Women’s Collective Ireland (WCI), Ronanstown, along with 319 Transition Year (TY) students from…

6 hours ago

NovaUCD and CeADAR Open Applications for 2026 AI Ecosystem Accelerator Programme

NovaUCD and CeADAR today announced that they are seeking applications from Irish-based AI start-ups to…

8 hours ago

Building a big ‘time crystal’ on IBM Quantum Heron

Researchers created a large, complex, two-dimensional “time crystal” on an IBM Quantum Heron r2 chip,…

10 hours ago

DeepWind, the new deepwater test site for offshore wind,

The European Marine Energy Centre (EMEC) has commenced an 18 month project to advance its…

11 hours ago

Microsoft launches 2026 Community Fund for South and West Dublin

Minister of State at the Department of Justice with special responsibility for Migration, and Dublin…

13 hours ago

How the 35% R&D Tax Credit Boosts Ireland’s MedTech R&D and Innovation Pipeline

Ireland’s MedTech sector is one of the country’s standout success stories. Ireland is home to…

1 day ago

More about Irish Tech News


Irish Tech News are Ireland’s No. 1 Online Tech Publication and often Ireland’s No.1 Tech Podcast too.


You can find hundreds of fantastic previous episodes and subscribe using whatever platform you like via our Anchor.fm page here: https://anchor.fm/irish-tech-news


If you’d like to be featured in an upcoming Podcast email us at Simon@IrishTechNews.ie now to discuss.


Irish Tech News have a range of services available to help promote your business. Why not drop us a line at Info@IrishTechNews.ie now to find out more about how we can help you reach our audience.


You can also find and follow us on Twitter, LinkedIn, Facebook, Instagram, TikTok and Snapchat.