Chipp.in Tech News and Reviews

Windows, Security & Privacy, Open Source and more

Menu
  • Home
  • Windows
  • Security & Privacy
  • Gaming
  • Guides
  • Windows 11 Book
  • Contact
  • RSS Feed
Menu
Malware

Three year old Malvertising Campaign is still going strong

Posted on August 13, 2024August 13, 2024 by Martin Brinkmann

One of the most important skills of any Internet user is the ability to distinguish between advertising and organic links. A core reason for that is that advertising is regularly abused for malvertising campaigns.

Malvertising refers to ads that in one way or another attack the user or the user’s device. A simple example is a download ad that pushes a malicious file onto the user’s system.

Security researchers at ReasonLabs have discovered a malvertising campaign that has been around for at least three years.

The details:

  • Polymorphic campaign that installs Chrome and Edge extensions on endpoints.
  • Uses multiple attacks, including search hijacking, stealing private data, or executing commands on the user’s device.
  • At least 300,000 users fell victim to the campaign until now.

How the attack works

The attackers use advertising to push malicious downloads. They use fake download sites for legitimate applications such as YouTube, VLC, or Roblox FPS Unblocker.

Users who fall for this, you guessed it, download a malicious payload to their systems. Here is what happens next:

  1. The executable creates a scheduled task, which is designed to run a PowerShell script.
  2. The PowerShell script downloads a payload from a remote server and runs it on the user’s machine.
  3. It then begins to make changes to the user’s system:
    • Adds policies to enforce the installation of Chrome and Edge installations from the Store (which are malicious).
    • Some versions of the script uninstall browser updates.
    • Tampers with browser .lnk file to load another extension for communication with a control server and stealing search queries.
    • Communicate with command center for status reports and the next stage of execution.

The script blocks uninstallation of the installed extensions, even when Developer Mode of the browser is set to on. Users will also see the “your browser is managed by your organization” message.

The blog post offers a deep dive, which interested or affected users may check out. There is also a section on removing the malware from infected hosts.

This involves:

  • Removing the scheduled tasks.
  • Removing the planted Registry keys.
  • Deleting the malicious files.

Closing Words

The security researchers note that many of the used domains, extensions, and scripts are not detected as malicious at the time of writing. Google and Microsoft were notified according to the blog post.

Which brings us right back to the beginning. Ads are not easily distinguishable from organic results in many cases. Google, for instance, displays a simple “sponsored” text above ads. They look exactly like organic results in any other way.

While experienced users may not have any problems differentiating between the two, less tech-savvy users fall for these.

So, if you want to improve security, you better take a good look at links before you click. If you want to be safer, do not click on ads 🙂

Tags:
Category: Security & PrivacyWindows

Post navigation

← Android Apps: Exodus reveals trackers and permissions before installation
Beyond hardware: these Pixel 9 features launch with the phones →

1 thought on “Three year old Malvertising Campaign is still going strong”

  1. TelV says:
    August 13, 2024 at 3:12 pm

    I think a better piece of advice would be to never allow ads to load in a user’s browser in the first place. Always use a recognized adblocker like uBlock Origin with the appropriate filters enabled, or a dedicated adblocker like Adguard.

    But I wonder to what degree youtube is complicit in the ads it accepts which, when added to videos may encourage users to inadvertently download malware.

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Support This Site

If you like what I do please support me!

Any tip is appreciated. Thanks!
  • January 15, 2026 by Martin Brinkmann Personal Intelligence: Google pivots Gemini towards an all-seeing AI
  • January 14, 2026 by Martin Brinkmann New Year, New Zero-Day: The January 2026 Windows Patch Tuesday Breakdown
  • January 13, 2026 by Martin Brinkmann Firefox 147 Just Dropped: 5 Features That Make It Worth Updating Today
  • January 12, 2026 by Martin Brinkmann WinSlop: The Open-Source Response to Microsoft’s AI Push—Strip the Bloat and Take Back Control of Your OS
  • January 11, 2026 by Martin Brinkmann Slimming Down: How Checkpoint Updates Are Making Windows 11 Faster

About

We talk, write and dream about Technology 24/7 here at Chipp.in. The site, created by Martin Brinkmann in 2023, focuses on well-researched tech news, reviews, guides, help and more.

Legal Notice

Our commitment

Many websites write about tech, but chipp.in is special in several ways. All of our guides are unique, and we will never just rehash news that you find elsewhere.

Read the About page for additional information on the site and its founder and author.

Support Us

We don't run advertisement on this site that tracks users. If you see ads, they are static links. Ads, including affiliate links, never affect our writing on this site.

Here is a link to our privacy policy

©2026 Chipp.in Tech News and Reviews