Numerous compromised websites are trying to trick users into installing malware by impersonating an update for Google's Chrome browser. After displaying the message below, a file named release.zip is downloaded. This zip file is NOT a Chrome update but Monero miner malware.
If you are tricked into running the zip file, you get the following:
Takeaway:
Only update Chrome from within the browser itself. Now would be a good time to check as Google released a new update yesterday, taking the version to 112.0.5615.86 or 87.
To check for real updates:
Definitions
Process injection - technique used by malware to inject code into a running process on a computer. This allows the malware to execute its code in a process already running in computer memory. This helps it evade detection and bypass security measures.
BYOVD (bring your own vulnerable driver) An attack that involves deliberately installing a vulnerable device driver and then using its vulnerability to exploit the device.
Source: Bleepingcomputer