logo

Hackers Using PUP Advertisements to Silently Drop Windows Malware

ID: ab2bbfda-15aa-58c1-8b8a-330fdda73874

STIX ID: report--ab2bbfda-15aa-58c1-8b8a-330fdda73874

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-08-25

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Researchers uncovered a widespread campaign delivering a stealthy Windows malware called ManualFinder via PUP-style ads that redirect users to spoofed installers. The attack chain uses MSHTA-executed JavaScript loaders and quiet MSI installs to establish persistence (scheduled tasks and services), recruit infected hosts into residential proxy networks, and in some instances harvest browser cookies and manipulate profiles for data exfiltration or monetization; investigators observed over 70 JavaScript variants and identified malicious domains and task/installer IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.