Friday, November 25th 2022

MSI Afterburner Laced with Malware Circulating in the Wild

MSI Afterburner is arguably the most popular graphics card overclocking utility, and the best place to find it is the MSI website. There are several other sites that redistribute the utility, many of them are trustworthy PC enthusiast tech publications; but some of them are not. There are some dubious websites that are using SEO techniques and ad-placements to find their way into online search results, appearing to be download mirrors for MSI Afterburner. While some of these sites are just in it for some web-traffic ad revenue, others downright spoof the MSI website (i.e. are visual clones), and host redistributables of Afterburner, only these have a more sinister motive—to infect you with malware.

Cybersecurity researchers at Cyble identified such spoof websites that are visually identical to the MSI website; which host modified versions of the Afterburner software laced with malware. This malware can infect your PC with a multitude of bad stuff, including cryptojacking (using your PC's system resources to mine cryptocurrency for the attacker); and data-theft. Cyble deconstructed the malware-laced Afterburner installer in a bid to identify its nature. Apparently it uses Monero XMR miner software to mine cryptocurrency. Apparently the attacker repackaged Afterburner into a custom installer that, in addition to installing Afterburner, fetches XMR miner from the Internet and infects Windows Explorer (explorer.exe) with a cryptojacking payload. The easiest way to avoid this is sticking to known sources such as the MSI website (www.msi.com); or known websites authorized to redistribute Afterburner. If infected, SFC (system file checker), coupled with Windows Defender or other popular antivirus software should help.
Sources: Cyble, HotHardware
Add your own comment

80 Comments on MSI Afterburner Laced with Malware Circulating in the Wild

#1
Arkz
Why would you ever get it from anywhere other than msi.com?
Posted on Reply
#3
Wavetrex
And then Google is Surprised Pikachu that people use ad-blockers.

Ads ARE the malware of the world !
Posted on Reply
#4
Vayra86
WavetrexAnd then Google is Surprised Pikachu that people use ad-blockers.

Ads ARE the malware of the world !
This.
Posted on Reply
#5
kapone32
This is why I use AMD software for my GPU.
Posted on Reply
#6
Merluz
JAB Creations*sigh*
"aftenburner" and "coconutcharcharcoal" in the first ad link, make me wonder if google is now the biggest and most effective scammer in the world.
Posted on Reply
#7
ZoneDymo
I like my Afterburner like I like my shoes,.....laced
Posted on Reply
#8
xorbe
Auftenburner, I like it. Zero hits on Google, it's mine!
Posted on Reply
#9
The King
kapone32This is why I use AMD software for my GPU.
If you download your AMD software from AMD.official,for.real.com then who do you blame?

Msi Afterburner still rocks people who download software from malicious websites have only themself to blame!

You can install free AV plugins from either Malwarebytes or BitDefender in your browser both are free and should block those sites even these downloads.
addons.mozilla.org/en-US/firefox/addon/malwarebytes/

addons.mozilla.org/en-US/firefox/addon/trafficlight/
Posted on Reply
#10
Kohl Baas
I never ever open anything from search results starting with "Ad". And even so I check the url just to be sure.

This on the internet is equivalent of looking around before crossing a road. You don't just throw yourself in front of a truck in good faith... :kookoo:
Posted on Reply
#11
Karti
On one hand, i am glad i am not forced to use that crap because of using CoreCTRL.. on other... you are forced to use that app full potential only on AMD gpu - because currently that app is linux only and we all know how Nvidia works there

tho if that app would be adopted for Windows brothers, then who knows
Posted on Reply
#13
Karti
Kohl BaasI never ever open anything from search results starting with "Ad". And even so I check the url just to be sure.

This on the internet is equivalent of looking around before crossing a road. You don't just throw yourself in front of a truck in good faith... :kookoo:
it is obvious to you, for me and other people here

tho let's face it - it is not that easily obvious to notice that for like bigger part of the people that are using internet
Posted on Reply
#14
trog100
i never use it i use palits thundermaster.. silly name but it works fine..

trog
Posted on Reply
#15
STSMiner
You should only be getting MSI Afterburner from two places

The developer for the app for MSI - Guru3d for the beta builds and final release builds.

or

MSI themselves
Posted on Reply
#16
GunShot
ArkzWhy would you ever get it from anywhere other than msi.com?
I asked the same exact question for other stuff too that I find super loco. e.g. Why would anyone ever get NVIDIA's, etc. drivers anywhere other than NVIDIA's OFFICIAL site? Why would anyone use any 3rd-party tools (DDU, etc.) to remove drivers rather than the vendors removal tools or system (Windows, etc.) baked-in tools? On and on.

But, many users make-up these very lame shilled/uninformed excuses (mainly due to others persuasions or because an old issue that happened moons ago or they just lack the talent and they need a quick so-called remedy) for today's issues. But, these same users that are utilizing these 3rd-party sources/apps are also wondering at times, why do they continue to have so many performance issues, etc.

WELP! :kookoo:
Posted on Reply
#18
W1zzard
JAB Creations*sigh*

I added your image to the news post, thanks :)
Posted on Reply
#20
ymdhis
JAB Creations*sigh*

Google search has really become horrible lately. It only has a few pages of results (even when it says it found millions of results, it'll cut them off after you get a few pages in), and it is riddled with fake content all the time. It keeps redirecting me to fake webshops very frequently. Not even just the "ad" results, but the ones below those.

It's incredibly unreliable nowadays.
Posted on Reply
#21
P4-630
JAB Creations*sigh*

I don't see those ads... Probably because I use uBlock Origin....Which more people should use imo....
Posted on Reply
#22
STSMiner
It's like the validation of some of these sites submitted to Google's search engine and others has gone down hill of late.
Posted on Reply
#23
b1k3rdude
This is not surpising to I imagine anyone that frequents TPU. And is yet another very good reason why you should at the very least, have an Ad blocker installed in your web browser.

Personally I have PiHole and Unbound(recursive DNS server) installed on a Pi2 to protect my LAN and then U-block origin on all my browsers on all my Desktop/laptops and Adaware on the phone. I have an extra step that if I read the article right blocks this path "injects XMR minor info exploere.exe", if the article is refering to windows explorer, I have that blocked from the internet and only allow access to the LAN via windows firewall, via WFC(WindowsFirewallControl). I block most of Windows10 services/programs from accessing the internet.
Posted on Reply
#24
BSim500
b1k3rdudeThis is not surpising to I imagine anyone that frequents TPU. And is yet another very good reason why you should at the very least, have an Ad blocker installed in your web browser.

Personally I have PiHole and Unbound(recursive DNS server) installed on a Pi2 to protect my LAN and then U-block origin on all my browsers on all my Desktop/laptops and Adaware on the phone. I have an extra step that if I read the article right blocks this path "injects XMR minor info exploere.exe", if the article is refering to windows explorer, I have that blocked from the internet and only allow access to the LAN via windows firewall, via WFC(WindowsFirewallControl). I block most of Windows10 services/programs from accessing the internet.
+1 for doing that but personally I don't even bother with a "black-list" Firewall (allow by default, block by exception) anymore. There's so much spyware and telemetry BS these days that I find running a white-list Firewall (block everything by default, allow by exception) is the only sane option.
Posted on Reply
#25
Bomby569
JAB Creations*sigh*

All this nice kind people paying for domains, servers and ads just to spread afterburner. The internet is a wonderful place.
Posted on Reply
Add your own comment
May 22nd, 2024 23:22 EDT change timezone

New Forum Posts

Popular Reviews

Controversial News Posts