Fireball Adware - Infected 250million Computers
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
The malware manipulates browsers to convert the default search engine to a fake search engine which eventually redirects queries to legitimate search engines, monetising the user's behaviour. Furthermore, it uses tracking pixels to collect user information but also has the ability to perform efficient malware dropping and remote code execution. Therefore, the security concern here is not over the primary purpose of the adware but the secondary functions it has the ability to perform which can be used for harvesting credentials, distributing malware or performing co-ordinated attacks.
Fireball is commonly bundled with programs such as Deal Wifi and Mustang Browser and uses sophisticated evasion techniques to avoid detection and analysis including a flexible Command and Control (C2) infrastructure. The adware is provided with digital certificates which makes the installation of the software seem even more trustworthy to unsuspecting users
Remediation steps
Last edited: 17 February 2020 11:30 am