216.73.216.6

HotPage: Story of a signed, vulnerable, ad-injecting driver

· Published 19/07/2024 15:37 · Modified 19/07/2024 16:03

Export JSON

Essential information

Published
19/07/2024 15:37
Modified
19/07/2024 16:03
Tags
2024-07-19 hotpage sys driver
Related entities
5 observables, 14 techniques (mitre), 1 malware

Description

This report investigates a sophisticated Chinese browser injector called , capable of injecting code into remote processes and intercepting network traffic to modify requested web pages, redirect users, or open new tabs based on rules. Despite claims of being a security solution, leverages vulnerabilities to perform malicious ad injection. The driver, signed by Microsoft, leaves systems open to privilege escalation attacks due to improper access controls. The analysis uncovers the malware's components, techniques, and the mysterious company behind it.

External references