Novel Chinese Browser Injector Lets Hackers Intercept Web Traffic
ID: 4422f840-aec0-56d7-b2e0-de39b1102d61
STIX ID: report--4422f840-aec0-56d7-b2e0-de39b1102d61
Feed Name: cybersecurityNews.com
ESET researchers identified HotPage.exe, a malicious installer deploying a Microsoft-signed kernel driver that poses as an "Internet cafe security solution" but injects libraries into Chromium-based browsers to redirect traffic, inject ads, hook SSL_read/write, collect system information, and enable arbitrary DLL injection and potential privilege escalation; Microsoft removed the vulnerable driver from the Windows Server Catalog on May 1, 2024, and ESET detects it as Win{32|64}/HotPage.A and Win{32|64}/HotPage.B.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
