Researchers observed an attack campaign distributing fake browser updates to infect website visitors with malware. The attackers inject links to an external script into a compromised webpage or the entire script code. In both cases, this code creates a message box informing the user that a critical error resulted from an outdated version of the web browser. It then prompts the visitor to update his or her browser version while displaying garbled text in the background to legitimize the appearance of a critical browser vulnerability. Once run, the file tries to download a Windows EXE file containing ransomware. By comparison, the Android version of this campaign downloads banking malware onto the infected device.”]

