Skip to main content

Fireball Adware - Infected 250million Computers

Researchers have discovered a new adware variant named Fireball. Fireball is believed to have been developed by a Chinese digital marketing agency for the sole purpose of creating revenue through click fraud.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Researchers have discovered a new adware variant named Fireball. Fireball is believed to have been developed by a Chinese digital marketing agency for the sole purpose of creating revenue through click fraud.

Threat details

The malware manipulates browsers to convert the default search engine to a fake search engine which eventually redirects queries to legitimate search engines, monetising the user's behaviour. Furthermore, it uses tracking pixels to collect user information but also has the ability to perform efficient malware dropping and remote code execution. Therefore, the security concern here is not over the primary purpose of the adware but the secondary functions it has the ability to perform which can be used for harvesting credentials, distributing malware or performing co-ordinated attacks.

Fireball is commonly bundled with programs such as Deal Wifi and Mustang Browser and uses sophisticated evasion techniques to avoid detection and analysis including a flexible Command and Control (C2) infrastructure. The adware is provided with digital certificates which makes the installation of the software seem even more trustworthy to unsuspecting users


Remediation steps

Type Step
  • Make sure that malware definitions are kept up-to-date.
  • Ensure all available security patches are deployed to desktop and server operating systems and security appliances.
  • Make sure that cyber awareness training is kept up-to-date.
  • Monitor network and proxy logs for indications of compromise.

Last edited: 17 February 2020 11:30 am