Careful with Brave.com for browser

Chat about just about anything else
Forum rules
Do not post support questions here. Before you post read the forum rules. Topics in this forum are automatically closed 30 days after creation.
Locked
gittiest personITW
Level 12
Level 12
Posts: 4286
Joined: Tue May 28, 2019 4:27 pm

Careful with Brave.com for browser

Post by gittiest personITW »

Just a heads up.....

https://informationsecuritybuzz.com/exp ... ty-expert/

https://www.topnormal.com/cybercriminals-spoof-brave-browser-website-to-push-malware/

To summarise,
If your Windows friends/families have downloaded the Brave browser recently, check if it was downloaded from brave.com which is where you would want to download the browser and not bravė.com
Very subtle difference but the sneaky scallies managed to get their malware downloaded onto a lot of machines.
It wouldn't affect Linux users by default as it is a .exe file but tell your Windows friends if they recently have started using Brave, as well as some other software including Tor and Telegram (according to the second link).
Last edited by LockBot on Wed Dec 07, 2022 4:01 am, edited 7 times in total.
Reason: Topic automatically closed 30 days after creation. New replies are no longer allowed.
User avatar
RickyRaccoon
Level 3
Level 3
Posts: 101
Joined: Mon May 02, 2016 3:46 pm

Re: Careful with Brave.com for browser

Post by RickyRaccoon »

Windows, Windows, Windows.... *clucks his tongue*

That IS pretty sneaky. I always install Brave for both Linux and Windows. Of course, even an amateur like me is still more observant than the average Windows user I suspect.
punkbiscuit
Level 3
Level 3
Posts: 123
Joined: Wed Feb 08, 2017 3:06 pm

Re: Careful with Brave.com for browser

Post by punkbiscuit »

Erm, and what is that crappy link that
you posted from topnormal that has
redirects to spam and malware itself.

The above post needs removing.
User avatar
karlchen
Level 23
Level 23
Posts: 18228
Joined: Sat Dec 31, 2011 7:21 am
Location: Germany

Re: Careful with Brave.com for browser

Post by karlchen »

Hello, punkbiscuit.

Virustotal does not confirm your statement. https://www.virustotal.com/gui/url/fa9d ... /detection
Telling from my own experience when visiting the topnormal site, it is obvious that it does not like my browser to suppress advertisements.
Funny thing is it then starts redirecting to (third-party / commercial?) ad-blockers, which my browser does not need. :?

Regards,
Karl
Image
The people of Alderaan have been bravely fighting back the clone warriors sent out by the unscrupulous Sith Lord Palpatine for 792 days now.
Lifeline
punkbiscuit
Level 3
Level 3
Posts: 123
Joined: Wed Feb 08, 2017 3:06 pm

Re: Careful with Brave.com for browser

Post by punkbiscuit »

On my Android phone I get an the redirects, then all the windows open
with adverts about I'm the 1 millionth viewer, my device is running slow, malware detected click for removal tools etc.

And then trying to get rid of the site in the browser won't work etc etc.

All the usual malware trickery stuff going on.

Certainly dangerous for mobile devices.

Sure won't be visiting that site again.

:-(
User avatar
karlchen
Level 23
Level 23
Posts: 18228
Joined: Sat Dec 31, 2011 7:21 am
Location: Germany

Re: Careful with Brave.com for browser

Post by karlchen »

Turned the second link into a textbox. So users will not be able to click on it simply and run into trouble potentially.
Image
The people of Alderaan have been bravely fighting back the clone warriors sent out by the unscrupulous Sith Lord Palpatine for 792 days now.
Lifeline
User avatar
JoeFootball
Level 13
Level 13
Posts: 4673
Joined: Tue Nov 24, 2009 1:52 pm
Location: /home/usa/mn/minneapolis/joe

Re: Careful with Brave.com for browser

Post by JoeFootball »

If interested, this is a detailed article that I read the other day ...

https://arstechnica.com/gadgets/2021/07 ... s-malware/
punkbiscuit
Level 3
Level 3
Posts: 123
Joined: Wed Feb 08, 2017 3:06 pm

Re: Careful with Brave.com for browser

Post by punkbiscuit »

Good plan Karlchen.
Locked

Return to “Open Chat”