logo

Microsoft-Signed Chinese Adware Opens the Door to Kernel Privileges

ID: 5f778e11-64e4-56ce-86e8-27769140039b

STIX ID: report--5f778e11-64e4-56ce-86e8-27769140039b

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-07-18

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

ESET researchers uncovered HotPage, a Microsoft-signed fake ad blocker marketed to Internet cafés that installs a vulnerable kernel-mode driver to inject/redirect ads, hook browser and network APIs, communicate with a C2, and allow arbitrary code execution at the highest privileges; Microsoft removed it from the Windows Server Catalog after ESET's report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.