{"id":20492,"date":"2020-12-13T11:52:35","date_gmt":"2020-12-13T16:52:35","guid":{"rendered":"https:\/\/www.thundercloud.net\/infoave\/new\/?p=20492"},"modified":"2020-12-14T07:17:41","modified_gmt":"2020-12-14T12:17:41","slug":"widespread-malware-campaign-affecting-chrome-firefox-and-microsoft-edge","status":"publish","type":"post","link":"https:\/\/www.thundercloud.net\/infoave\/new\/widespread-malware-campaign-affecting-chrome-firefox-and-microsoft-edge\/","title":{"rendered":"Widespread Malware Campaign Affecting Chrome, Firefox, and Microsoft Edge"},"content":{"rendered":"<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 18pt;\"><strong><span style=\"font-family: helvetica, arial, sans-serif;\">Widespread Malware Campaign Affecting Chrome, Firefox, and Microsoft Edge<\/span><\/strong><\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full\" src=\"https:\/\/thundercloud.net\/infoave\/images\/2021\/mwarning.png\" alt=\"Cloudeight Malware Warning\" width=\"474\" height=\"254\" \/><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Our mission is to help you with your computer and to help keep you safe. Yesterday, I read a blog post from one of Microsoft security blogs that captured my attention.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\"><em>Before we get started, if you&#8217;re using <a href=\"https:\/\/thundercloud.net\/emsisoft\/\" target=\"_blank\" rel=\"noopener\">Emsisoft<\/a>, you&#8217;re protected from this malware and its variants.\u00a0<\/em><\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">In a report last Thursday, December 10, Microsoft issued a warning to users of four major web browsers:\u00a0 Google Chrome, Mozilla Firefox, Microsoft Edge, and Yandex browsers, that a widespread malware attack affecting all four browsers is spreading rapidly around the globe.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">According to <a href=\"https:\/\/tinyurl.com\/y4rhcgko\" target=\"_blank\" rel=\"noopener\">Microsoft 365 Defender Research Team&#8217;s blog&#8230;<\/a><\/span><\/p>\n<blockquote><p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">A persistent malware campaign has been actively distributing an evolved browser modifier malware at scale since at least May 2020. At its peak in August, the threat was observed on over 30,000 devices every day. The malware is designed to inject ads into search engine results pages. The threat affects multiple browsers\u2014Microsoft Edge, Google Chrome, Yandex Browser, and Mozilla Firefox\u2014exposing the attackers\u2019 intent to reach as many Internet users as possible.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">We call this family of browser modifiers Adrozek. If not detected and blocked, Adrozek adds browser extensions, modifies a specific DLL per target browser, and changes browser settings to insert additional, unauthorized ads into web pages, often on top of legitimate ads from search engines. The intended effect is for users, searching for certain keywords, to inadvertently click on these malware-inserted ads, which lead to affiliated pages. The attackers earn through affiliate advertising programs, which pay by amount of traffic referred to sponsored affiliated pages.<\/span><\/p>\n<p>&nbsp;<\/p>\n<blockquote><p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full\" src=\"https:\/\/thundercloud.net\/infoave\/images\/2021\/unaffected.png\" alt=\"Browser Malware\" width=\"599\" height=\"844\" \/><\/span><br \/>\n<span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Image from Microsoft<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\"><img decoding=\"async\" class=\"size-full\" src=\"https:\/\/thundercloud.net\/infoave\/images\/2021\/affected.png\" alt=\"Browser Malware\" \/><\/span><br \/>\n<span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Image from Microsoft<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Cybercriminals abusing affiliate programs is not new\u2014browser modifiers are some of the oldest types of threats. However, the fact that this campaign utilizes a piece of malware that affects multiple browsers is an indication of how this threat type continues to be increasingly sophisticated. In addition, the malware maintains persistence and exfiltrates website credentials, exposing affected devices to additional risks.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Such a sustained, far-reaching campaign requires an expansive, dynamic attacker infrastructure. We tracked 159 unique domains, each hosting an average of 17,300 unique URLs, which in turn host more than 15,300 unique, polymorphic malware samples on average. In total, from May to September 2020, we recorded hundreds of thousands of encounters of the Adrozek malware across the globe, with heavy concentration in Europe and in South Asia and Southeast Asia. As this campaign is ongoing, this infrastructure is bound to expand even further&#8230;<\/span><\/p><\/blockquote>\n<\/blockquote>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\"><a href=\"https:\/\/tinyurl.com\/y4rhcgko\" target=\"_blank\" rel=\"noopener\"><strong>You can read the entire Microsoft blog post here.<\/strong><\/a>\u00a0<\/span><\/p>\n<p><strong><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Emsisoft protects against this threat&#8230;<\/span><\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full\" src=\"https:\/\/thundercloud.net\/infoave\/images\/2021\/mzblock.png\" alt=\"Emsisoft protects against this malware threat.\" width=\"600\" height=\"387\" \/><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; &nbsp; Widespread Malware Campaign Affecting Chrome, Firefox, and Microsoft Edge Our mission is to help you with your computer and to help keep you safe. Yesterday, I read a blog post from one of Microsoft security blogs that captured my attention. Before we get started, if you&#8217;re using Emsisoft, you&#8217;re protected from this malware and its variants.\u00a0\u2026 <span class=\"read-more\"><a href=\"https:\/\/www.thundercloud.net\/infoave\/new\/widespread-malware-campaign-affecting-chrome-firefox-and-microsoft-edge\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":14573,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1462,2574,2659,1669,2660,3590,1680,779],"tags":[4129],"_links":{"self":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/20492"}],"collection":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/comments?post=20492"}],"version-history":[{"count":6,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/20492\/revisions"}],"predecessor-version":[{"id":20498,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/20492\/revisions\/20498"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/media\/14573"}],"wp:attachment":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/media?parent=20492"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/categories?post=20492"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/tags?post=20492"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}