Warning: New Adware Campaign Targets Meta Quest App Seekers
ID: 2086c3cf-270e-5c66-ad5a-bd9f50f17576
STIX ID: report--2086c3cf-270e-5c66-ad5a-bd9f50f17576
Feed Name: The Hacker News
eSentire reported a campaign delivering a new PowerShell-based adware family named AdsExhaust via SEO-poisoned fake Meta Quest (Oculus) download sites. The initial lure is a ZIP containing batch scripts that chain-load additional scripts and payloads, create scheduled tasks, drop VBS/PowerShell to gather system info and screenshots, and fetch the AdsExhaust payload from a C2 (us11.org/in.php). AdsExhaust can detect idle Edge browser sessions, simulate keystrokes/clicks, perform automated searches, inject overlays, close browsers on user interaction, and exfiltrate screenshots, all to fraudulently generate ad revenue; the report also notes related loader/infostealer activity (Hijack Loader/Vidar and Adwind).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
