Stealthy Ad-Based Malware Campaign Targets Windows Users via PUPs
ID: d8cf55f9-bed2-5048-a42a-01b17a102419
STIX ID: report--d8cf55f9-bed2-5048-a42a-01b17a102419
Feed Name: Cyber Press
Researchers at Expel uncovered an ad-driven malware campaign in which apparently legitimate productivity apps (e.g., ManualFinder, OneStart, AppSuite-PDF, PDF Editor) are distributed via deceptive landing pages and bundled MSI installers that silently deploy trojans. The malware achieves persistence through scheduled tasks and Node.js-executed JavaScript droppers in %TEMP%, abuses code-signing certificates from questionable entities, connects to known malicious domains (mka3e8.com), and in some cases converts victim machines into residential proxies; the report provides IoCs and hunting/mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
