Nigelthorn Malware: Chrome Users Beware | WheelHouse I

Once again, there is an example of why all users need to be careful about what they install. This time, however, users of the Google Chrome browser are the ones being specifically targeted by a particularly nasty attack known as “Nigelthorn.”

Nigelthorn’s Method of Attack

When scrolling on Facebook, a user may see what appears to be a link to a YouTube video, but is actually a fake. This fraudulent video will then inform the user that in order for it to be played, an extension from the Chrome Web Store, called “Nigelify,” has to be installed. In reality, installing the extension allows the malware into the user’s system.

In order to fool its way past the Chrome Web Store defenses, Nigelthorn’s code is implanted into an extension that has already passed the Web Store’s checks. The first extension to be infected was one called “Nigelify,” which would replace all the pictures on the page a user was viewing with images of Nigel Thornberry, a late 1990s/early 2000s cartoon character who has found new life as a meme.

Once Nigelthorn is installed, it can have various effects on the infected system. For instance, not only will this attack vector steal the data that is available through Facebook, it will also share itself via Facebook Messenger, or by tagging the original victim’s friends. This makes it very effective at spreading from victim to victim, as all it takes to infect the next person in line is for them to install the infected extension as well.

Nigelthorn has also been found to use other common tools found in malware in order to accomplish the goal of its developer, including crypto-mining and YouTube manipulation for financial gain.

Getting Rid of Nigelthorn Malware

(and Avoiding It in the First Place)

What’s worse is that once Nigelthorn has been installed, it is notoriously hard to get rid of.

If you have inadvertently installed Nigelthorn, it will automatically close the extensions panel, preventing you from uninstalling it. This means that removing it will likely require you to uninstall Chrome. If you are unlucky enough to be infected, you should change your Google and Facebook credentials in case they were stolen by the malware.

As for avoiding Nigelthorn, the surest path is to not click on the link. As long as the user in question knows not to click on suspicious links or install additional extensions without careful consideration, using Chrome is still workably safe. Google has since removed the identified infected extensions from the Chrome Web Store, but similar browser-based threats continue to emerge regularly.

Protect Your Business from Browser-Based Threats Like Nigelthorn

Attacks like Nigelthorn are a reminder that cybersecurity threats can come from unexpected places, including the apps and extensions employees install every day. For businesses, the stakes are even higher: a single infected device can expose company data, client records, and network infrastructure to attackers.

The best defense combines employee awareness with proactive security monitoring. Training your team to recognize suspicious links and unsolicited prompts to install browser extensions goes a long way toward prevention. Pairing that awareness with managed threat detection and response helps ensure that if something does slip through, it is caught and contained before it can spread.

If you are concerned about your organization’s exposure to browser-based malware and other cybersecurity threats, start with a complimentary risk assessment from WheelHouse IT. Our team of security specialists will evaluate your environment, identify vulnerabilities, and provide clear recommendations to keep your business protected.

Ready to take the next step? Reach out to WheelHouse IT today:

Contact Us Today and check out our blog for more cybersecurity tips and updates.