Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Quiz sites trick users into enabling unwanted browser notifications

0
Medium
Published: Tue Mar 10 2026 (03/10/2026, 12:56:28 UTC)
Source: AlienVault OTX General

Description

Users are being tricked into enabling unwanted browser notifications through quiz websites. These sites challenge visitors with quizzes on various topics, but their main goal is to get users to click 'Start the quiz' button. This action triggers a misleading prompt that tricks users into allowing notifications. Once enabled, these notifications can display advertisements, scams, or unwanted downloads even when the user is not on the original website. The article provides instructions on how to remove and block web push notifications across different browsers, including Chrome, Firefox, Opera, Edge, and Safari. It also lists several domains associated with this deceptive campaign.

AI-Powered Analysis

AILast updated: 03/10/2026, 13:33:31 UTC

Technical Analysis

This threat involves a deceptive campaign where quiz websites lure users into enabling browser push notifications under false pretenses. The sites present quizzes on various topics to entice users to click a 'Start the quiz' button, which triggers a misleading browser prompt requesting permission to send notifications. Users who accept this prompt inadvertently allow the site to send persistent notifications that can display advertisements, scams, or links to unwanted downloads even when the user is not actively browsing the site. The campaign exploits social engineering tactics (T1566) and user interaction (T1204) to bypass browser security controls. The notifications act as a persistent adware vector, potentially leading to further malicious payloads or phishing attempts. The campaign is distributed via multiple domains, many localized to regions such as New Zealand (.co.nz), India (.co.in), and South Africa (.co.za), indicating targeted regional activity. The threat does not exploit a software vulnerability but abuses legitimate browser features and user trust. There are no known exploits in the wild beyond the social engineering mechanism. The campaign is documented by AlienVault OTX and referenced in security analyses, with guidance provided for removing and blocking notifications across major browsers including Chrome, Firefox, Opera, Edge, and Safari.

Potential Impact

The primary impact is on user experience and security posture, as unwanted notifications can lead to persistent adware infections, exposure to scams, and potential malware downloads. Organizations face risks of compromised endpoint security if users fall victim and install malicious payloads via these notifications. The campaign can degrade productivity due to intrusive notifications and increase helpdesk workload for remediation. While it does not directly compromise system integrity or confidentiality, it serves as a vector for further attacks, including phishing and malware distribution. The broad geographic distribution of domains suggests a wide potential reach, particularly in countries with high internet penetration and use of browsers supporting push notifications. The campaign may also damage brand reputation if employees or customers are targeted. The lack of authentication or complex exploitation lowers the barrier for attackers, increasing the likelihood of widespread impact.

Mitigation Recommendations

1. Educate users to be cautious about enabling browser notifications, especially from unfamiliar or suspicious websites. 2. Implement browser policies via group policy or MDM solutions to restrict or control push notification permissions in enterprise environments. 3. Regularly audit and remove unwanted notification permissions from browsers on organizational devices. 4. Use web filtering and DNS blocking to prevent access to known malicious domains listed in the indicators. 5. Deploy endpoint security solutions capable of detecting and blocking adware and malicious payloads delivered via notifications. 6. Monitor network traffic for unusual outbound connections or repeated notification permission requests. 7. Encourage users to report suspicious notifications promptly to IT security teams. 8. Keep browsers and security software up to date to leverage the latest protections against social engineering and adware. 9. Consider browser extensions or security tools that warn or block deceptive notification prompts. 10. Integrate threat intelligence feeds to update blocklists dynamically with emerging malicious domains.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://securityboulevard.com/2026/03/quiz-sites-trick-users-into-enabling-unwanted-browser-notifications/"]
Adversary
null
Pulse Id
69b014fc00119187bccbf395
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domaindailyrumour.co.nz
domainedifaqe.org
domaingenisfun.co.nz
domaingeniusfun.co.in
domaingeniusfun.co.za
domainivenih.org
domainloopdeviceconnection.co.in
domainnavixzuno.co.in
domainquizcentral.co.in
domainquizcentral.co.za
domainrixifabed.org
domaintriviabox.co.in
domainuhuhedeb.org
domainunsphiperidion.co.in
domainyeqeso.org
domainylloer.org

Threat ID: 69b01a1eea502d3aa8553b3c

Added to database: 3/10/2026, 1:18:22 PM

Last enriched: 3/10/2026, 1:33:31 PM

Last updated: 3/14/2026, 2:26:15 AM

Views: 167

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console in Console -> Billing for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses