Anatomy of a Scamware Network—MultiPlug
ID: 751ff1ac-f352-532a-80b6-f017e55d028a
STIX ID: report--751ff1ac-f352-532a-80b6-f017e55d028a
Feed Name: Zscaler Security Research Blog
**Executive summary:** Zscaler researchers uncovered a large-scale MultiPlug scamware campaign that uses search-poisoning lures and signed installers to distribute adware/spyware; the campaign uses 33 Certum/Unizeto code-signing certificates to sign 2,783 binaries hosted across 447 hosts (323 domains), achieves persistence (service 'compfix'), installs modified Chrome DLLs and browser add-ons that resist removal, and exfiltrates system data via HTTP POST — enterprises should treat even seemingly benign adware as a security risk due to its persistence and payload delivery capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
