Forum Moderators: open

Message Too Old, No Replies

Multiple Browsers Affected By Ongoing Malware Campaign

         

engine

5:14 pm on Dec 11, 2020 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Microsoft's 365 Defender research team says that a persistent malware campaign is distributing browser modifier malware, Adrozek, at scale, and it affects multiple browsers, including Microsoft Edge, Google Chrome, Yandex Browser, and Mozilla Firefox.
https://www.microsoft.com/security/blog/wp-content/uploads/2020/12/Fig4-Adrozek-attack-chain.png
We call this family of browser modifiers Adrozek. If not detected and blocked, Adrozek adds browser extensions, modifies a specific DLL per target browser, and changes browser settings to insert additional, unauthorized ads into web pages, often on top of legitimate ads from search engines. The intended effect is for users, searching for certain keywords, to inadvertently click on these malware-inserted ads, which lead to affiliated pages. The attackers earn through affiliate advertising programs, which pay by amount of traffic referred to sponsored affiliated pages.
After tampering with multiple browser components and settings, the malware gains the capability to inject ads on search results on affected browsers. The injection of ads is performed by malicious scripts downloaded from remote servers.


It's worth reading the whole piece from Microsoft.
[microsoft.com...]

graeme_p

4:02 pm on Dec 12, 2020 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Only in Windows, right?

tangor

9:47 pm on Dec 12, 2020 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Why I surf with all scripting turned off.