typetechniquecreated2026-07-28updated2026-07-28c2-protocolevasionmitre-attck

Chrome 128 User-Agent Masquerade

Malware hardcodes a fake Google Chrome User-Agent string to masquerade its HTTP requests as legitimate browser traffic. The version number is often absurd or impossible (e.g., Chrome/7775543322.0.0.0 or Chrome/128.0.0.0), which makes the string trivial to detect but also serves as a family fingerprint.

Detection / Fingerprint

Look for WinInet or WinHTTP requests where the User-Agent header contains:

  • Chrome/ followed by a version component that is clearly non-existent (7775543322, 128 with no sub-version, or other out-of-range numbers).
  • The full Phorpiex variant: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/7775543322.0.0.0 Safari/537.36

Implementation Patterns Observed

The UA string is passed as the lpszAgent parameter to InternetOpenW in WinInet-based downloaders. In the Phorpiex campaign the same UA string is reused across multiple compiled binaries, making it a high-signal network IOC.

Reproduce on Your Own VMs

Compile a minimal C/C++ program that calls:

HINTERNET hInternet = InternetOpenW(
    L"Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
    L"AppleWebKit/537.36 (KHTML, like Gecko) "
    L"Chrome/7775543322.0.0.0 Safari/537.36",
    INTERNET_OPEN_TYPE_DIRECT,
    NULL, NULL, 0);

Then fetch any URL via InternetOpenUrlW + InternetReadFile. Observe the outgoing User-Agent in a packet capture or proxy log.

Defensive Countermeasures

  • Proxy / firewall rules blocking or alerting on User-Agent containing Chrome/7775543322 or similar impossible version strings.
  • EDR network telemetry rules for processes that are not browsers but emit Chrome User-Agent strings.

Pages Where Observed

  • phorpiex — campaign-level abuse of this masquerade across thin-downloaders and the business-app masquerade variant 9570038453.
  • Phorpiex thin-downloader siblings (6b8527a7, 2ffc3203, 32f29422, f67e429d, 025f5798).