Blurred Lines: AdTech Abuse Delivers Browser Hijackers Through the Microsoft Store
ID: 354009bd-46ee-5f4c-94b1-3c6470f1284a
STIX ID: report--354009bd-46ee-5f4c-94b1-3c6470f1284a
Feed Name: Trinity Cyber Blog
Threat Score
Trinity Cyber describes an active campaign that uses typo-squatted domains and an AdTech-based pseudo TDS (PseudoTDS) to funnel users to Microsoft Store PWAs that deploy a previously undocumented browser hijacker called PhantomJack; the malware can read bookmarks and history, install unauthorized extensions, and change default search engines, and researchers identified ~45 landing domains, GTAG identifiers and 16 active apps in the Microsoft Store.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
