News: 1607634366

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft warns of ad-scamming, credential-stealing malware hitting Edge, Chrome, Firefox, Yandex browsers

(2020/12/10)


On Thursday Microsoft warned that there's an ongoing campaign to distribute malware that modifies web browsers to conduct credential theft and ad fraud.

Since at least May, 2020, unidentified cybercriminals have been distributing a family of browser modifiers dubbed Adrozek, Microsoft said. The code, which targets Google Chrome, Microsoft Edge, Mozilla Firefox, and Yandex Browser on Windows, mainly injects ads into search results pages.

"If not detected and blocked, Adrozek adds browser extensions, modifies a specific DLL per target browser, and changes browser settings to insert additional, unauthorized ads into web pages, often on top of legitimate ads from search engines," the Microsoft 365 Defender Research Team said its [1]blog post .

"The intended effect is for users, searching for certain keywords, to inadvertently click on these malware-inserted ads, which lead to affiliated pages."

Chrome extensions are 'the new rootkit' say researchers linking surveillance campaign to Israeli registrar Galcomm [2]READ MORE

The attackers make their money through participation in advertising affiliate programs, which pay for the online traffic referred to specific web pages. To date, these ads don't appear to point to sites hosting other malware, but Microsoft suggests that could change at any time.

In Firefox, Adrozek also scans the victim's device for stored user credentials and sends what it finds to the attacker.

Such attacks and tactics have been seen before, but according to Microsoft, the scale and complexity of the campaign, targeting multiple browsers via distributed infrastructure, shows cybercriminals becoming more sophisticated in their efforts.

Microsoft said it has detected 159 unique domains, each hosting an average of 17,300 unique URLS that each host more than 15,300 unique, polymorphic malware samples on average. Its systems measured hundreds of thousands of contacts with Adrozek malware, mainly in Europe, South Asia, and Southeast Asia. And the campaign is ongoing.

This distribution system offers up software for download that unwitting victims run. The installer drops a randomly named .exe file that installs a primary payload disguised as legitimate audio software in the Windows Program Files folder. The installed code then makes changes to various browser components and settings to enable ad injection and credential theft.

Adrozek also attempts to alter browser DLLs, such as MsEdge.dll in Microsoft Edge so changes to the Secure Preferences file won't be noticed. In Chromium-based browsers, it modifies a security-related hash integrity check used to prevent tampering. It also adds a policy to prevent the browsers it subverts from being updated.

Microsoft says that its Defender Antivirus, which ships with Windows 10, can defend against Adrozek. And it advises those who find the malware on their system to reinstall their browser. ®

Get our [3]Tech Resources



[1] https://www.microsoft.com/security/blog/2020/12/10/widespread-malware-campaign-seeks-to-silently-inject-ads-into-search-results-affects-multiple-browsers/

[2] https://www.theregister.com/2020/06/18/chrome_browser_extensions_new_rootkit/

[3] https://whitepapers.theregister.com/

UN-bundled goodness

Mahhn

"Microsoft says~~~ And it advises those who find the malware on their system to reinstall their browser."

Well it's a pretty darn good thing that MS was required by governments to UN-bundled IE to the OS, or everyone effected would have to reinstall windows and not just their browser.

Anonymous Coward

On the bright side, one of the sites mentioned in the linked Microsoft article appears to have GREAT deals on Windows and Office licenses!

/s

https://urlscan.io/screenshots/88723589-841e-4d3b-b1c7-0e18c53e37b7.png

OS?

a_yank_lurker

From the reference to dll's, I assume this has only been seen on Bloatware and not other OSes but is this assumption correct. If so, why are the dll's modifiable through the browser?

End of the world.

JimPoak

Well we are all doomed (Except for Linux users for now). I don't think anybody really cares about advertising Fraternity being screw over for fees. What does concern me "stored user credentials" Shopping,Backing,local services and Email accounts makes phishing expeditions pointless. Why try to trick someone into giving up an email address when you can waltz-in and take it. Java Script has a lot to answer for. A special crafted scrip can access any part of your computer and other computing devices connected on a network (my router for instance).

Still it's only Microsoft.

Thus spake the master programmer:
"Without the wind, the grass does not move. Without software,
hardware is useless."
-- Geoffrey James, "The Tao of Programming"