Heimdal data reveals MediaArena adware completes persistence before antivirus quarantine finishes
ID: 67656022-228c-5510-b0b0-922ab5278255
STIX ID: report--67656022-228c-5510-b0b0-922ab5278255
Feed Name: Heimdal Security Blog
**Heimdal telemetry finds MediaArena adware establishes persistence before quarantine completes.** Heimdal observed in live customer environments that MediaArena writes its persistence to disk ~21 seconds after execution while Microsoft Defender quarantine finished ~29 seconds after execution, meaning persistence is in place before quarantine completes; the pattern was seen across 40+ clients and one timed case showed signature-based detection took ~78 days to remove the hijacker, so Heimdal advises treating quarantine alerts as the start of an investigation and checking endpoints for persistence artefacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
