This ‘Privacy Browser’ Has Dangerous Hidden Features

-


The Universe Browser makes some big promises to its potential users. Its online advertisements claim it’s the “fastest browser,” that people using it will “avoid privacy leaks” and that the software will help “keep you away from danger.” However, everything likely isn’t as it seems.

The browser, which is linked to Chinese online gambling websites and is thought to have been downloaded millions of times, actually routes all internet traffic through servers in China and “covertly installs several programs that run silently in the background,” according to new findings from network security company Infoblox. The researchers say the “hidden” elements include features similar to malware—including “key logging, surreptitious connections,” and changing a device’s network connections.

Perhaps most significantly, the Infoblox researchers who collaborated with the United Nations Office on Drugs and Crime (UNODC) on the work, found links between the browser’s operation and Southeast Asia’s sprawling, multibillion-dollar cybercrime ecosystem, which has connections to money-laundering, illegal online gambling, human trafficking, and scam operations that use forced labor. The browser itself, the researchers says, is directly linked to a network around major online gambling company BBIN, which the researchers have labeled a threat group they call Vault Viper.

The researchers say the discovery of the browser—plus its suspicious and risky behavior—indicates that criminals in the region are becoming increasingly sophisticated. “These criminal groups, particularly Chinese organized crimes syndicates, are increasingly diversifying and evolving into cyber enabled fraud, pig butchering, impersonation, scams, that whole ecosystem,” says John Wojcik, a senior threat researcher at Infoblox, who also worked on the project when he was a staff member at the UNODC.

“They’re going to continue to double down, reinvest profits, develop new capabilities,” Wojcik says. “The threat is ultimately becoming more serious and concerning, and this is one example of where we see that.”

Under the Hood

The Universe Browser was first spotted—and mentioned by name—by Infoblox and UNODC at the start of this year when they began unpacking the digital systems around an online casino operation based in Cambodia, which was previously raided by law enforcement officials. Infoblox, which specializes in domain name system (DNS) management and security, detected a unique DNS fingerprint from those systems that they linked to Vault Viper, making it possible for the researchers to trace and map websites and infrastructure linked to the group.

Tens of thousands of web domains, plus various command-and-control infrastructure and registered companies, are linked to Vault Viper activity, Infoblox researchers say in a report shared with WIRED. They also say they examined hundreds of pages of corporate documents, legal records, and court filings with links to BBIN or other subsidiaries. Time and time again, they came across the Universe Browser online.

“We haven’t seen the Universe Browser advertised outside of the domains Vault Viper controls,” says Maël Le Touz, a threat researcher at Infoblox. The Infoblox report says the browser was “specifically” designed to help people in Asia—where online gambling is largely illegal—bypass restrictions. “Each of the casino websites they operate seem to contain a link and advertisement to it,” Le Touz says.



Source link

Ariel Shapiro
Ariel Shapiro
Uncovering the latest of tech and business.

Latest news

Gear News of the Week: There’s Yet Another New AI Browser, and Fujifilm Debuts the X-T30 III

An increasingly popular solution is the inclusion of a solar panel to keep that battery topped up, enabling...

Don’t Let the Fuzzy Rats Win: Tips from a Squirrel Hater Who’s Seen It All

Squirrels: Are they just rats with better PR? Be advised that this is not safe reading material for...

OpenAI’s Atlas Wants to Be the Web’s Tour Guide. I’m Not Convinced It Needs One

The oddest, and most memorable, interaction I had with ChatGPT Atlas occurred as I scrolled around on Bluesky...

The Pepsi Man Is Coming to Save Samsung From Boring Design

Samsung has one of the biggest product line ups of any tech brand, yet when it comes to...

The Best Couples’ Sex Toys to Spice Up the Bedroom or Long Distance Fun

Other Sex Toys to ConsiderHere are a few other toys that aren't as great as the picks above...

DHS Wants a Fleet of AI-Powered Surveillance Trucks

The US Department of Homeland Security is seeking to develop a new mobile surveillance platform that fuses artificial...

Must read

You might also likeRELATED
Recommended to you