Skip to main content

Threats Tagged 'adware'

View all threats tagged with 'adware'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: adware

Threats Tagged 'adware'

Click on any threat for detailed analysis and mitigation recommendations

A sophisticated campaign deployed 148 malicious npm packages disguised as student web proxy applications under brands like Riverbend Tutoring and Northstar Tutoring. Published by accounts terminal3airport and eerikakirk, these packages weaponized visitor browsers into distributed denial-of-service botnets while generating advertising revenue. The applications functioned as working proxies but secretly executed mutable remote code and high-performance WebSocket traffic generators compatible with the Wisp protocol. During a critical two-week period in May 2026, active deployments launched HTTP floods generating 2GB/s aggregate traffic and control-plane attacks establishing 10,240 socket connections per second against target servers. The campaign abused npm as a content delivery network, affecting users who visited proxy instances rather than through traditional dependency infection.

Join the discussion

ModHeader, a popular Chrome developer extension with over 800,000 users, was flagged and removed by Google for containing hidden spyware. Version 7.0.18 included a covert SDK disguised as a date library (dayjs) that harvested visited domain names, encrypted them using AES-GCM, and was configured to upload the data daily to api.stanfordstudies.com. Although the collection remained dormant due to an empty allowlist, the complete exfiltration infrastructure was present and operational. Additionally, the extension displayed active adware behavior, opening affiliate tabs on every update including on enterprise-managed machines. The malicious code shipped with official Chrome Web Store signatures, affecting both Chrome and Edge users. Forensic analysis revealed the extension locally stored 178MB of sensitive HTTP headers from all browsing activity, though no data was successfully exfiltrated from analyzed systems.

Join the discussion

SearchJack represents a coordinated campaign comprising 23 deceptive Chrome browser extensions that silently hijack users' default search engines, redirecting queries through monetization middleware before delivering results. These extensions masquerade as various productivity tools, satellite imagery viewers, maps, and news readers while their actual purpose is generating search affiliate revenue. The campaign affects approximately 758,000 users across 22 unique publishers and leverages at least 8 distinct monetization brokers, primarily routing traffic through Yahoo Hosted Search affiliate programs. The extensions employ manifest-only wrappers using chrome_settings_overrides to hijack search settings, with some implementing runtime obfuscation to evade static analysis. Several extensions feature false privacy claims, anomalous review patterns, and anonymous publishers with fictional corporate identities, enabling operators to monetize user search behavior while maintaining zero accountability.

Join the discussion

Users are being tricked into enabling unwanted browser notifications through quiz websites. These sites challenge visitors with quizzes on various topics, but their main goal is to get users to click 'Start the quiz' button. This action triggers a misleading prompt that tricks users into allowing notifications. Once enabled, these notifications can display advertisements, scams, or unwanted downloads even when the user is not on the original website. The article provides instructions on how to remove and block web push notifications across different browsers, including Chrome, Firefox, Opera, Edge, and Safari. It also lists several domains associated with this deceptive campaign.

Join the discussion

This threat involves three advanced browser hijacking techniques targeting Firefox and Chrome browsers. The first technique modifies browser preference files directly to alter settings such as default search engines and homepage configurations. The second, known as BRAT (Browser Remote Access Tool), remotely simulates key presses to manipulate browser behavior, including opening unwanted tabs and changing search engines. The third exploits a Chromium command line switch to load malicious extensions while disabling browser updates to maintain persistence. These methods enable attackers to control browser behavior stealthily, potentially leading to user tracking, ad fraud, or further malware deployment. Although no known exploits are currently active in the wild, the techniques demonstrate evolving sophistication in browser hijacking. The threat is rated medium severity due to its potential impact on user privacy and browser integrity, combined with moderate exploitation complexity. European organizations relying heavily on Chrome and Firefox browsers should be vigilant, as these browsers are widely used across the continent. Detection and mitigation require enhanced monitoring of browser configuration files, command line parameters, and unusual input simulation activities. Proactive measures are essential to prevent persistent hijacking and maintain browser security integrity.

Join the discussion

The 'GhostAd' campaign is a large-scale Android adware threat that infiltrated Google Play with seemingly benign apps embedding persistent background advertising engines. These apps exploited Android foreground services, job schedulers, and continuous ad refreshing to maintain presence and aggressively display ads without user interaction, causing significant battery drain, degraded device performance, and difficulty in removal. Although primarily impacting users in East and Southeast Asia, the adware's use of legitimate advertising SDKs complicates detection and removal. Google has removed the malicious apps and disabled them via Google Play Protect. European organizations with Android device fleets could face indirect impacts such as reduced device availability and user productivity if similar apps spread. Mitigation requires proactive app vetting, enhanced endpoint monitoring for abnormal resource usage, and user education on app permissions and removal techniques. Countries with high Android adoption and significant Google Play usage, such as Germany, France, and the UK, are more likely to be affected if the campaign expands. Given the medium severity rating, the threat poses a moderate risk primarily through resource exhaustion and user disruption without direct data compromise or remote exploitation.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Tag: adware
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses