The browser is an item that must be installed on everyone’s computer, and it seems that hijacking the browser to carry out malicious behavior is expected to happen sooner or later. Microsoft recently disclosed a piece of malware called “Adrozek” that hijacked browsers including Chrome, Firefox, and Edge. At its peak, it controlled at least 30,000 devices every day.

Microsoft reveals “Adrozek” malware, which hijacks Chrome, Firefox and Edge
If you find that some strange and unusual advertisements often appear when surfing the Internet in your computer browser, then you should be careful. Your computer may have inadvertently downloaded malware. Hundreds of thousands of installations were detected around the world between May and September 2020. It is estimated that the actual number of infected users is higher than expected. The victims are mostly concentrated in Europe, followed by South Asia and Southeast Asia.

This malware named “Adrozek” has been active on the Internet since at least May 2020, and reached its peak in August this year. Specifically, starting in May, Microsoft tracked 159 domains hosting Adrozek installers, and each domain also hosted an average of 17,300 dynamically generated URLs, with a further 15,300 dynamically generated Adrozek installers per URL.

Microsoft said the malware was distributed through a typical phishing method, in which hackers redirected users from legitimate websites to suspicious domain names and tricked users into installing the malware. Once installed on the user’s computer, Adrozek will automatically identify the browser installed on the computer. If Microsoft Edge, Google Chrome, Mozilla Firefox or Yandex browser is found on the infected computer, the malware will try to force the installation of extension plug-ins by modifying the browser application data folder. What’s even more insidious is that in order to prevent the browser’s security features from activating and detecting abnormal behavior, Adrozek also modified some browsed DLL files, changed browser settings and disabled security features, including:
- Disable browser updates
- Disable archive integrity checking
- Disable Safe Browsing
- Register and launch the extension added in the previous step
- Allows malicious extensions to run in incognito mode
- Allow extensions to run without appropriate permissions
- Hide extension from toolbar
- Modify your browser’s default homepage
- Modify your browser’s default search engine

The purpose of all these actions is to allow Adrozek to insert ads into search results pages and earn revenue by directing traffic to ads and recommended applications. To make matters worse, on Firefox, Adrozek also has an auxiliary function that can extract credentials such as personal passwords from the browser and upload the stolen data to a remote server.

Microsoft said that the scope of Adrozek’s influence is likely to expand. If you find that your browser has the above-mentioned anomalies, you may be harmed by malware. Users can reinstall the browser, but there is no official explanation as to whether this can completely solve the problem.
◎Data source:Microsoft
Source: KOCPC Chinese