Choziosi (Windows)

Aliases: ChromeLoader

First seen
2022-01-01 00:00:00
Malware type
spyware
Family
Malware family
Last IoC activity
2026-07-21 00:33:46
Profile updated
2026-07-07 14:35:41

Targeted industries: media-and-entertainment retail-and-hospitality technology-and-telecommunications

Context

Choziosi is a browser hijacker for Chrome. It was first seen in January 2022. It commonly infects users via pirated media downloads like games, software, wallpapers or movies. The initial infectors are available for several platforms such as Mac and Windows. Its main component is the Chrome browser extension written in JavaScript with the purpose of serving advertisments and hijacking search requests to Google, Yahoo and Bing.

Reports & references

  • github.com — Cs Installer (report)
  • redcanary.com — Chromeloader (report)
  • blogs.blackberry.com — Chromeloader Infects The Browser By Loading Malicious Extension (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Choziosi (report)
  • connectwise.com — Smash Jacker (report)
  • blogs.vmware.com — The Evolution Of The Chromeloader Malware (report)
  • gdatasoftware.com — 37236 Qr Codes On Twitter Deliver Malicious Chrome Extension (report)
  • cybergeeks.tech — Chromeloader Browser Hijacker (report)

External references