Shift Browser is signed adware that fingerprints your endpoint before it drops payload
ID: fcb26026-d55c-511b-9839-cc158a93a006
STIX ID: report--fcb26026-d55c-511b-9839-cc158a93a006
Feed Name: Heimdal Security Blog
Heimdal MXDR detected a surge of Shift Browser installer detections (50+ clients on 2 Sep 2026) delivered via malvertising disguised as PDF tools; sandbox analysis returned a Malicious verdict showing system fingerprinting (T1033, T1012, T1082), persistence and dropped executable content (chrome.packed.7z), and the samples are code-signed by Shift Technologies Inc while several vendors label it a PUP/adware; recommended actions include blocking confirmed hashes, watching for the "shift – pdf_*" naming pattern, alerting on the rapid MITRE technique sequence, and avoiding allow-listing based on signature alone.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
