logo

Blurred Lines: AdTech Abuse Delivers Browser Hijackers Through the Microsoft Store

ID: 354009bd-46ee-5f4c-94b1-3c6470f1284a

STIX ID: report--354009bd-46ee-5f4c-94b1-3c6470f1284a

Feed Name: Trinity Cyber Blog

Threat Score
72/100

Date Published: 2025-11-05

Date Updated: 2026-05-01

Author: Trinity Cyber

...
...

Trinity Cyber describes an active campaign that uses typo-squatted domains and an AdTech-based pseudo TDS (PseudoTDS) to funnel users to Microsoft Store PWAs that deploy a previously undocumented browser hijacker called PhantomJack; the malware can read bookmarks and history, install unauthorized extensions, and change default search engines, and researchers identified ~45 landing domains, GTAG identifiers and 16 active apps in the Microsoft Store.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.