What is fake browser update malware?
Fake browser update malware is a form of deceptive content placed on or loaded through a compromised website. The page imitates a browser or software warning and attempts to persuade the visitor to download a file or take another unsafe action.
Google classifies pages that pretend to be a trusted entity in order to make somebody perform a dangerous action as social engineering. Its guidance specifically includes deceptive content that encourages visitors to download unwanted software.
On WordPress, the visible warning may be generated by injected JavaScript, a modified theme or plugin, database content or a remote resource loaded into an otherwise legitimate page. Attackers can also make the behaviour conditional. The site owner may see the normal website while another device or visitor is shown the false update.
Do not download or open the file offered by the fake message as part of your investigation.
How to check a site showing fake browser updates
Record the affected URL and the circumstances in which the message appeared. Check the page from a different device, including a phone, but do not interact with suspicious download buttons. If the issue was reported by a customer, note whether they arrived from Google or another referring site.
Open Google Search Console and review Security Issues. Google says deceptive or social-engineering content detected on a site can be reported there. Check the Pages report as well for URLs you did not create and review property ownership for unfamiliar verified users.
Inspect the affected page source and loaded scripts for resources you do not recognise, especially additions to page headers or files that have changed unexpectedly. Compare WordPress core with trusted originals and inspect plugins and themes rather than limiting the check to visible page content. Review the database for unfamiliar scripts or values that could be inserted into page output.
Our free WordPress security scanner can provide an additional outside view of the site, but it should not replace file, database and hosting checks when visitors have seen a malicious download prompt.
How to remove fake browser update malware
- Take a full copy first. Preserve all WordPress files and the database and keep the infected copy for investigation and evidence.
- Secure the accounts. Change WordPress, hosting, database and FTP or SFTP passwords. Replace the WordPress salts in wp-config.php and remove unauthorised users.
- Find the injected code. Trace the false update prompt to the script, database record, plugin, theme or configuration that generates or loads it.
- Restore clean code. Replace compromised WordPress core and legitimate plugin or theme files with clean copies where appropriate and remove malicious database content.
- Look for secondary access. Check for backdoors and other altered files rather than stopping after the popup disappears.
- Close the original entry point. Patch or remove vulnerable software and secure any account or hosting access that was compromised.
After cleaning, test the conditions that previously displayed the fake update and recheck Search Console. Our Hacked Site Rescue is £349 fixed price.
How to reduce the risk of another fake update infection
Keep WordPress core and actively used plugins and themes updated. Delete extensions you no longer need rather than merely deactivating them, particularly when they are no longer maintained.
Use strong unique passwords, enable two-factor sign-in where available and limit administrator privileges to people who need them. File integrity checks are useful for spotting unexpected changes to scripts and PHP files between legitimate releases.
Keep complete off-server backups containing both files and the database. Continue monitoring Search Console and investigate new security warnings promptly.
Care plans start from £59 a month and include weekly updates, daily off-server backups, uptime monitoring and security scanning. More information is available on our WordPress maintenance page.