logo

HotPage: Story of a signed, vulnerable, ad-injecting driver

ID: b45cf1c2-f7aa-53a5-b58e-ef8d21b5e199

STIX ID: report--b45cf1c2-f7aa-53a5-b58e-ef8d21b5e199

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
75/100

Date Published: 2024-07-18

Date Updated: 2026-05-01

...
...

ESET Research analyzes HotPage (DwAdsafe), an ad-injecting installer that deploys a Microsoft-signed kernel driver and browser-hooking libraries to intercept and modify browser network traffic, inject ads, change homepages, and exfiltrate basic system information; the driver’s improper access controls allow arbitrary processes to misuse its injection capabilities and enable local privilege escalation to SYSTEM. The report includes technical details of the installer, driver, injected libraries, redirection methods, proof-of-concept escalation scenarios, IoCs (hashes, IPs, domains), and mitigation context (driver removal from the Windows Server Catalog).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.