Microsoft-Signed Chinese Adware Opens the Door to Kernel Privileges
ID: 5f778e11-64e4-56ce-86e8-27769140039b
STIX ID: report--5f778e11-64e4-56ce-86e8-27769140039b
Feed Name: Dark Reading
Threat Score
ESET researchers uncovered HotPage, a Microsoft-signed fake ad blocker marketed to Internet cafés that installs a vulnerable kernel-mode driver to inject/redirect ads, hook browser and network APIs, communicate with a C2, and allow arbitrary code execution at the highest privileges; Microsoft removed it from the Windows Server Catalog after ESET's report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
