logo

Anatomy of a Scamware Network—MultiPlug

ID: 751ff1ac-f352-532a-80b6-f017e55d028a

STIX ID: report--751ff1ac-f352-532a-80b6-f017e55d028a

Feed Name: Zscaler Security Research Blog

Threat Score
60/100

Date Published: 2025-09-18

Date Updated: 2026-05-01

...
...

**Executive summary:** Zscaler researchers uncovered a large-scale MultiPlug scamware campaign that uses search-poisoning lures and signed installers to distribute adware/spyware; the campaign uses 33 Certum/Unizeto code-signing certificates to sign 2,783 binaries hosted across 447 hosts (323 domains), achieves persistence (service 'compfix'), installs modified Chrome DLLs and browser add-ons that resist removal, and exfiltrates system data via HTTP POST — enterprises should treat even seemingly benign adware as a security risk due to its persistence and payload delivery capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.