Hackers Using Microsoft Edge Malvertising Campaign To Target Users

Risk:
high
Damage:
high
Platform(s):
Microsoft
Advisory ID:
ngCERT-2022-0095
Version:
N/A
CVE:
N/A
Published:
September 26, 2022

Summary


A malicious advertising campaign has been unearthed on the Microsoft Edge Browser News Feed that redirects victims to fraudulent tech support websites. Cybercriminals have resorted to posting bizarre, attention-grabbing stories or advertisements on the Edge news feed in order to entice users to click on them. This is a type of malvertising – online advertisements that appear legitimate but contain malware and/or other threats.

Description & Consequence


The Microsoft Edge News Feed is the default page that appears when a new tab is opened, and it displays information such as news, advertisements, weather, and traffic updates. The following are the steps that result in being redirected to a bogus tech support page:

  1. The user clicks on a story or advertisement.
  2. The Edge browser settings is analysed for various metrics.
  3. Based on the aforementioned metrics and prior results, if the user is adjudged to be a bot or in a location that is not of interest, s/he is redirected to a harmless dummy page that is relevant to the story or advertisement s/he initially clicked on.
  4. However, if the user is adjudged a potential victim, then s/he is redirected to a tech support scam website for further exploitation.

If a victim falls for the tech support website scam, it could lead to:

  1. The harvesting of their Personally-Identifiable Information (PII) and other data.
  2. Being infected with malware.

Solution


Below are some countermeasures that will lessen one’s chances of falling victim:

  1. It is pertinent to practice safe internet browsing habits and to refrain from clicking on links one is unsure of.
  2. Install a trusted, up-to-date anti-virus software that has an internet security component.
  3. Customize News Feed in Microsoft Edge Browser.

Reference


Revision


Related Articles