Exploring how an authorized and signed driver exposed vulnerabilities to potential hazards – Security Insights with Tony Anscombe

Visualization
A purported ad blocker presented as a protective measure exploits a Microsoft-endorsed driver, inadvertently putting victims at risk of severe threats

How a legitimate and signed driver left the doors open to threats – Week in Security with Tony Anscombe

Visualization

A purported ad blocker presented as a protective measure exploits a Microsoft-endorsed driver, inadvertently putting victims at risk of severe threats

This week, ESET researchers have published their discoveries on HotPage, a browser injector that utilizes a driver created by a Chinese firm and endorsed by Microsoft.

The malicious software poses as an “Internet café security solution” boasting ad-blocking features. However, in reality, it showcases ads related to games and has the ability to alter or substitute requested page content, direct users to alternative pages, or launch a new tab under specified conditions.

In addition, it inadvertently creates a gateway for other threats to initiate code execution at the highest privilege level in Windows – the SYSTEM account.

Tune in as Tony delves into the details and elaborates on why misuse of certificates continues to be a pressing concern.

Follow us on FacebookTwitterLinkedIn and Instagram.

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.