logo

MediaArena malvertising: why a quarantine isn’t the end of the incident

ID: 9630bddd-b967-5401-9289-135552ee6d51

STIX ID: report--9630bddd-b967-5401-9289-135552ee6d51

Feed Name: Heimdal Security Blog

Threat Score
55/100

Date Published: 2026-07-17

Date Updated: 2026-08-06

Author: Alexandru Gurgu

...
...

Active malvertising campaign distributing BrowserModifier:Win32/MediaArena via fake "AI" recipe apps (GiveMeRecipe, KitchenCanvas, FoodFormula). Installers require no admin rights, drop persistence artefacts to AppData, Start Menu/Startup and an HKCU Uninstall key, and inject the loader (math.dll) in memory; quarantine often occurs after persistence is written. Indicators include kitchen-canvas.com, givemerecipe.com, d3pth7js01bstg.cloudfront.net and sample hashes; investigators should hunt for Startup shortcuts and HKCU Uninstall keys rather than relying solely on file quarantine.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.