In plain sight: Malicious ads hiding in search results

Sometimes there’s more than just an enticing product offer hiding behind an ad. One thing is true: Malware developers are deeply invested in improving their malware and exploring different ways to compromise end users. Malware spreading through ads is nothing new; for a long time, cybercriminals have had their sights fixed on online advertising networks as a distribution … More In plain sight: Malicious ads hiding in search results

HotPage browser injector capable of replacing web content and redirecting users

HotPage browser injector is capable of replacing web content and opens the system to other vulnerabilities. ESET Research has discovered a sophisticated browser injector: This threat, which ESET dubbed HotPage, comes self-contained in an executable file that installs its main driver and injects libraries into Chromium-based browsers. Posing as a security product capable of blocking … More HotPage browser injector capable of replacing web content and redirecting users

The ABCs of how online ads can impact children’s well-being

From promoting questionable content to posing security risks, inappropriate ads present multiple dangers for children. Here’s how to help them stay safe. In today’s digital world, ads are practically unavoidable. From pop-up ads on your daily Wordle to sneaky affiliate posts on your favorite social media accounts, we are constantly bombarded with targeted marketing messages … More The ABCs of how online ads can impact children’s well-being

Birthday Reminder looks benign but the devil’s in the details: Hooks DNS, serves dodgy ads

The strange behavior of a simple Windows application caught our attention and sparked ESET’s analysis of previously undocumented malware. A contact at the Norwegian HealthCERT —  following a question about this from the regional healthcare provider Sykehuspartner — reached out to us asking about DNS queries to domains with the format [0-9a-f]{60}.smoke. There is no .smoketop level domain, … More Birthday Reminder looks benign but the devil’s in the details: Hooks DNS, serves dodgy ads