Friday, November 25th 2022

MSI Afterburner Laced with Malware Circulating in the Wild

MSI Afterburner is arguably the most popular graphics card overclocking utility, and the best place to find it is the MSI website. There are several other sites that redistribute the utility, many of them are trustworthy PC enthusiast tech publications; but some of them are not. There are some dubious websites that are using SEO techniques and ad-placements to find their way into online search results, appearing to be download mirrors for MSI Afterburner. While some of these sites are just in it for some web-traffic ad revenue, others downright spoof the MSI website (i.e. are visual clones), and host redistributables of Afterburner, only these have a more sinister motive—to infect you with malware.

Cybersecurity researchers at Cyble identified such spoof websites that are visually identical to the MSI website; which host modified versions of the Afterburner software laced with malware. This malware can infect your PC with a multitude of bad stuff, including cryptojacking (using your PC's system resources to mine cryptocurrency for the attacker); and data-theft. Cyble deconstructed the malware-laced Afterburner installer in a bid to identify its nature. Apparently it uses Monero XMR miner software to mine cryptocurrency. Apparently the attacker repackaged Afterburner into a custom installer that, in addition to installing Afterburner, fetches XMR miner from the Internet and infects Windows Explorer (explorer.exe) with a cryptojacking payload. The easiest way to avoid this is sticking to known sources such as the MSI website (www.msi.com); or known websites authorized to redistribute Afterburner. If infected, SFC (system file checker), coupled with Windows Defender or other popular antivirus software should help.
Sources: Cyble, HotHardware
Add your own comment

80 Comments on MSI Afterburner Laced with Malware Circulating in the Wild

#26
DeathtoGnomes
Again?

I think this happened before, agessssss ago if it did.


People that have malware either do it intentionally or are completely stupid and should have their devices and computer taken away like...I was gonna say "like some little kid" but then it dawned on me (no crack of Dawn jokes please), its prolly little kids getting the malware and the parents reporting it. This makes the parents just as stupid for not teaching the kids properly.
Posted on Reply
#28
bug
JAB Creations*sigh*

The real sad part is that you don't even expect people to understand what those links mean anymore :(

Edit: And if you modify the installer, the signature is invalidated, which raises the question: do these modified installers carry a proper signature?
Posted on Reply
#29
kapone32
The KingIf you download your AMD software from AMD.official,for.real.com then who do you blame?

Msi Afterburner still rocks people who download software from malicious websites have only themself to blame!

You can install free AV plugins from either Malwarebytes or BitDefender in your browser both are free and should block those sites even these downloads.
addons.mozilla.org/en-US/firefox/addon/malwarebytes/

addons.mozilla.org/en-US/firefox/addon/trafficlight/
LOL. Many people today take things at face value without context, you get what you deserve if you do that but why should that site exist. I download it from the Adrenline software when it says download though. Other than that AMD is one of my favorites so it comes up first as soon as I type in AMD.
Posted on Reply
#30
Jism
And this is exactly why you use an adblock. You cant trust party's like google, FB, IG nothing no more with their automation routine check on ads.

Tip: Adblock + Ublock at the same time.
Posted on Reply
#31
bug
JismAnd this is exactly why you use an adblock.
Because you can't read URLs? That's not why I use one.
Posted on Reply
#32
ThomasK
Google getting paid to show results with ads containing virus, malware and whatnot.

What a whack job.
Posted on Reply
#33
Jism
bugBecause you can't read URLs? That's not why I use one.
Its obviously because of the "Adv" elements on Google search for example.

You block those. But also other partners. Its a shame we came to this point but really you cant trust the majority of these advertisement platforms anymore.
Posted on Reply
#34
SirB
SomeOne99hLong time ago, MSI released a beta version, but I couldn't find it in their site, and tried then to dig their site but find nothing. Only guru3D would help me on this.
This time MSI is uploading the beta version in their site as the main version.
Umm, because 3D Guru developed it. MSI really has nothing to do with this software besides paying to have their name on it.
Posted on Reply
#35
neatfeatguy
People aren't going to change. Folks still tend to click through popups when they install things.

You could literally have a popup say "Clicking YES will install a virus. Do you wish to continue?" And they'll just click on YES.

Best you can do is try to keep people informed.
Posted on Reply
#36
ThrashZone
Hi,
Yeah duckduckgo and start page work just fine at finding msi's website on top
Start page being the best of course at finding all legitimate download site :cool:



Even found bleeping computers article :laugh:
Posted on Reply
#37
64K
People don't seem to know basic things about PCs. A friend of mine got one of those ransom things where you can't close the screen out in the normal way and it wouldn't let him log off from his browser. I showed him how to use Task Manager to close the browser.
Posted on Reply
#38
CrAsHnBuRnXp
WavetrexAnd then Google is Surprised Pikachu that people use ad-blockers.

Ads ARE the malware of the world !
I dont care who the business is, im running an adblocker no matter what and never turn it off for any reason.
Posted on Reply
#39
bug
64KPeople don't seem to know basic things about PCs. A friend of mine got one of those ransom things where you can't close the screen out in the normal way and it wouldn't let him log off from his browser. I showed him how to use Task Manager to close the browser.
Right up there with "oh no, the browser didn't open on google.com, where do I enter the URL?".
Posted on Reply
#40
natr0n
use ublock origin youll never see shit like that. unblock it here on TPU of course.

laced with...makes me think of fentanyl btw
Posted on Reply
#41
b1k3rdude
BSim500+1 for doing that but personally I don't even bother with a "black-list" Firewall (allow by default, block by exception) anymore. There's so much spyware and telemetry BS these days that I find running a white-list Firewall (block everything by default, allow by exception) is the only sane option.
I can see your point and WFC is basically doing that already as EVERTHING has to request access, and I only allow stuff through.
Posted on Reply
#42
lexluthermiester
For some perspective, this is what I see when looking for anything, including Afterburner;


The situation described in this article is exactly why adblockers are so important and critical. It does not matter that things like this happen once in a while, they happen and such is unacceptable. We can't count on the likes of big corporations(not just Google, these kinds of things happen on microsoft's own Bing search frequently as well) to protect us, that responsibility is our own. AdBlockers and other privacy & security tools are critical to the general public protecting itself.
natr0nuse ublock origin youll never see shit like that.
Agreed. UBlock is excellent, but it's not the only good adblocker out there.
natr0nunblock it here on TPU of course.
Also agree with this point. TPU is one of the few places on the net that is actually ad safe. W1zzard takes personal pride in this place and actually cares about the visitors, audience and forum users.
Posted on Reply
#43
bug
lexluthermiesterFor some perspective, this is what I see when looking for anything, including Afterburner;


The situation described in this article is exactly why adblockers are so important and critical. It does not matter that things like this happen once in a while, they happen and such is unacceptable. We can't count on the likes of big corporations(not just Google, these kinds of things happen on microsoft's own Bing search frequently as well) to protect us, that responsibility is our own. AdBlockers and other privacy & security tools are critical to the general public protecting itself.


Agreed. UBlock is excellent, but it's not the only good adblocker out there.

Also agree with this point. TPU is one of the few places on the net that is actually ad safe. W1zzard takes personal pride in this place and actually cares about the visitors, audience and forum users.
Fwiw, I don't get those whether I enable the ad blocking or not. Do ad blockers really block Google's own ads on google.com?
Posted on Reply
#44
caroline!
JAB Creations*sigh*

I mean. It's g**gle after all, eww.

Half the site must be ads by now, I pity the poor souls who don't know about adblockers yet.
"msl aftenburner" and "mci" are there lol, and it works on any crd! gives you coplete control!
Posted on Reply
#45
the54thvoid
Intoxicated Moderator
bugFwiw, I don't get those whether I enable the ad blocking or not. Do ad blockers really block Google's own ads on google.com?
Yeah, I'm on mobile (chrome with Google) and the first three results are all genuine MSI, and the 4th result is an article about the malware.

Is this because I'm using a Pixel device in Google's environment so I'm not getting ads? I don't use adblockers.
Posted on Reply
#46
erek
ZoneDymoI like my Afterburner like I like my shoes,.....laced
Haha
Posted on Reply
#47
noel_fs
why make such a sensational post
Posted on Reply
#48
lexluthermiester
bugDo ad blockers really block Google's own ads on google.com?
Oh yes!
noel_fswhy make such a sensational post
How do you not understand this problem?
Posted on Reply
#49
Dammeron
xorbeAuftenburner, I like it. Zero hits on Google, it's mine!
Auftenburner... Someone went really german on that one. :D
Posted on Reply
#50
Dr. Dro
kapone32This is why I use AMD software for my GPU.
Haha and when I brought up that NVIDIA not offering a first-party GPU tweaking tool was actually a major problem, I was just told "why would anyone or NVIDIA for that matter care about something like this when MSI Afterburner exists?"

I am *so* jumping ship.
Posted on Reply
Add your own comment
Jun 15th, 2024 21:44 EDT change timezone

New Forum Posts

Popular Reviews

Controversial News Posts