• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
WebSetNet

WebSetNet

Technology News

  • Technology News
    • Mobile
    • Games
  • Internet Marketing
  • System Admin
    • Windows 11
    • Linux
    • Mac & Apple
    • Website Scripts
      • Wordpress
You are here: Home / Technology News / Microsoft Warns About Malware Campaign Infecting Chrome, Edge, And Firefox

Microsoft Warns About Malware Campaign Infecting Chrome, Edge, And Firefox

December 23, 2020 by justin26

microsoft

Microsoft on Thursday warned in a blog post about a new malware campaign that is designed to silently inject ads into search results, affecting multiple browsers, including Microsoft Edge, Google Chrome, Yandex Browser, and Mozilla Firefox.

According to Microsoft, a persistent malware campaign has been actively distributing an evolved browser modifier malware at scale since at least May 2020. In August 2020, the threat was its peak where over 30,000 devices were infected by the malware every day.

“We call this family of browser modifiers Adrozek. If not detected and blocked, Adrozek adds browser extensions, modifies a specific DLL per target browser, and changes browser settings to insert additional, unauthorized ads into web pages, often on top of legitimate ads from search engines,” the Microsoft Team wrote.

“The intended effect is for users, searching for certain keywords, to inadvertently click on these malware-inserted ads, which lead to affiliated pages. The attackers earn through affiliate advertising programs, which pay by amount of traffic referred to sponsored affiliated pages.”

According to the Microsoft Team, browser modification malware isn’t necessarily new or all that advanced, but the fact that this campaign utilizes a piece of malware that affects multiple browsers is an indication of how this threat type continues to be increasingly sophisticated. Besides, the malware maintains persistence and exfiltrates website credentials, exposing affected devices to additional risks.

Microsoft’s tracking of the Adrozek campaign from May to September 2020 saw 159 unique domains used to distribute hundreds of thousands of unique malware samples, each hosting an average of 17,300 unique URLs, which in turn host more than 15,300 unique, polymorphic malware samples on average.

From May to September 2020, the Redmond tech giant recorded hundreds of thousands of encounters of the Adrozek malware across the globe, with a heavy concentration in Europe, South Asia, and Southeast Asia.

The Adrozek malware is installed on devices through a drive-by download. Attackers depended heavily on polymorphism, which allows them to churn huge volumes of samples as well as to evade detection.

The distribution infrastructure is also very dynamic. Some of the domains were up for just one day, while others were active for longer up to 120 days. Interestingly, some of the domains were distributing clean files like Process Explorer, which was likely an attempt by the attackers to improve the reputation of their domains and URLs and evade network-based protections.

Microsoft has described Adrozek’s attack chain in the image below:

As can be seen in the image above, the installer from the domain drops a .exe file with a random file name in the %temp% folder. This file in drops the main payload in the Program Files folder using a file name that makes it look like legitimate audio-related software. The malware uses various names like Audiolava.exe, QuickAudio.exe, and converter.exe.

Once installed, Adrozek makes multiple changes to the browser settings and components including the default homepage, adds new browser extensions, changes the in-browser DLL files, browser’s default search engine, updates schedule, permissions settings, and much more, in order to allow the malware to inject ads into search engine result pages.

If this was not enough, in Mozilla Firefox, the Adrozek malware also steals user credentials from the browser which are then communicated back to the attacker’s servers.

“While many of the domains hosted tens of thousands of URLs, a few had more than 100,000 unique URLs, with one hosting almost 250,000. This massive infrastructure reflects how determined the attackers are to keep this campaign operational,” Microsoft added.

Microsoft advises end-users who find this malware on their devices to reinstall their browsers. Further, it also added that users should educate themselves about preventing malware infections and the risks of downloading and installing software from untrusted sources and clicking ads or links on suspicious websites.

As a precautionary measure, end-users should ensure that their security software and operating systems are up to date. As for enterprises, they should look to reduce the attack surface by implementing application control to enforce the use of only authorized apps and services.

The post Microsoft Warns About Malware Campaign Infecting Chrome, Edge, And Firefox appeared first on TechWorm.

Related posts:

  1. The Ultimate Guide to Google Ads [Examples]
  2. New GeForce drivers optimized for Call of Duty: WWII
  3. How to Create a Revenue-Generating Google Ads Campaign
  4. The Ultimate Guide to Amazon Advertising
  5. Responsive Search Ads: 5 Best Practices for Google Ads PPC Search Campaigns
  6. Microsoft Windows Security Updates September 2020 overview
  7. How to Create a Revenue-Generating Google Ads Campaign
  8. Microsoft December 2020 Patch Tuesday fixes 58 vulnerabilities
  9. Domain Hunter Gatherer Review
  10. The Ultimate Guide to Google Search Console in 2021

Filed Under: Technology News Tagged With: campaign, infecting, malware, Microsoft, warns

Primary Sidebar

Popular posts

  • 5 Ways to Fix “Your SIM sent a Text Message” Issue on iPhone
  • 3 Ways to Disable GetApps on Xiaomi, Redmi, and Poco Phones Running MIUI
  • GeForce Experience not finding games? Fix it fast
  • How To Extract & Install tar.gz Files In Ubuntu
  • How to Highlight Duplicates in Google Sheets
  • Discord Stream Has No Sound? 6 Ways to Fix
  • How to check if your Android device supports Widevine DRM
  • Exclamation Mark on Network Signal, Mobile Data Not Working? 8 Ways to Fix
  • How to find a lost Apple Pencil using your iPad (1st and 2nd gen)
  • 8 Best Sites to Read Manga Online for Free
  • 3 Ways to Hide Tabs in Google Chrome
  • How to Fix YouTube Server Connection Error [400] on Android
  • How to Track a Stolen or Lost Nintendo Switch
  • How To Search On Google Using Image or Video
  • How To Calculate CAGR in Excel
  • Microsoft Edge's newest feature? Shopping in Microsoft Edge
  • How to Change the Last Modified Date, Creation Date, and Last Accessed Date for Files and Folders

Footer

Tags

Amazon android Apple Asus available download: edge feature features first free from galaxy Game games gaming gets google install Intel iPhone launches linux Microsoft more OnePlus phone release released review: samsung series support this Ubuntu update using video watch what will windows with xbox your

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org