Video
An alleged ad blocker promoted as a security measure utilizes a Microsoft-approved driver that unintentionally subjects individuals to perilous risks
21 Jul 2024
Throughout this week, ESET experts have shared their discoveries on HotPage, a browser injection tool that utilizes a driver created by a Chinese company and endorsed by Microsoft.
The malicious software disguises itself as an “Internet café security feature” with ad-blocking functionalities. Nevertheless, it exhibits advertisements related to games and has the ability to alter or supplant the content of a requested page, direct the user to an alternate page, or launch a new page in a fresh tab depending on specific conditions.
Furthermore, it inadvertently creates an avenue for additional threats to execute code at the utmost privilege level within Windows – the SYSTEM account.
Observe as Tony explores the story and elaborates on how the misuse of certificates remains a prevalent concern.
Engage with us on Facebook, Twitter, LinkedIn and Instagram.

