Arab Press

بالشعب و للشعب
Monday, Apr 06, 2026

Microsoft Warns 'Adrozek' Malware is Infecting Thousands of PCs to Insert Ads

Microsoft Warns 'Adrozek' Malware is Infecting Thousands of PCs to Insert Ads

'We recorded hundreds of thousands of encounters of the Adrozek malware across the globe, with heavy concentration in Europe and in South Asia and Southeast Asia,' Microsoft said.

A new malware strain has been spreading to hundreds of thousands of Windows PCs in an effort to inject unauthorized ads into users’ search results, according to Microsoft.

The company has been tracking "Adrozek," a malware family capable of modifying multiple browsers including Google’s Chrome, Microsoft’s Edge and Mozilla’s Firefox in order to insert the ads into search result pages.

“At its peak in August, the threat was observed on over 30,000 devices every day,” Microsoft warned in a blog post on Thursday.

Inserting the ads into your search results is certainly annoying. But the real threat is how the malware can also steal login credentials from the Firefox browser, and potentially give hackers a launching pad for more damaging crimes.

Adrozek works by modifying a browser’s Dynamic Link Libraries or DLL files to change the settings, including turning off the security safeguards and the automatic updates. The result can place links to ads alongside legitimate ads, as the example below shows.



“The intended effect is for users, searching for certain keywords, to inadvertently click on these malware-inserted ads, which lead to affiliated pages,” Microsoft said. “The attackers earn through affiliate advertising programs, which pay by amount of traffic referred to sponsored affiliated pages.”

To deliver the malware, the hackers have been resorting to drive-by downloads. This can occur when a user clicks on a malicious link or visits a website that’s been tampered with. The PC will trigger the malware to download, which can sometimes install itself on the computer by exploiting a software vulnerability.

Hence, it’s a good idea to always keep your browser up to date. In other cases, the user will install the malware from a drive-by download, believing it to be a safe program.



In this case, Adrozek will drop an .exe file in the PC’s “temp” folder. The .exe file will then deliver the main malware payload in the “Programs Files” folder using a file name such as “Audiolava.exe, QuickAudio.exe, and converter.exe,” Microsoft said.

The company tracked Adrozek’s distribution to 159 unique domains, which hosted tens of thousands of URLs to try and spread the malware.

“In total, from May to September 2020, we recorded hundreds of thousands of encounters of the Adrozek malware across the globe, with heavy concentration in Europe and in South Asia and Southeast Asia,” Microsoft added. “As this campaign is ongoing, this infrastructure is bound to expand even further.



Although the malware is so far aimed at inserting unauthorized ads, Microsoft is concerned Adrozek could one day be used for more malicious crimes, such as redirecting users to scam websites. The good news is that the company’s built-in Windows Defender antivirus can detect and block Adrozek.

“End users who find this threat on their devices are advised to re-install their browsers,” the company added.


Newsletter

Related Articles

Arab Press
0:00
0:00
Close
Iranian Drone Strike on US Embassy in Saudi Arabia Reportedly Targeted Intelligence Facility
Saudi Deputy Foreign Minister Meets French Embassy Official to Strengthen Bilateral Engagement
Saudi Arabia Calls on United States to Seize Strategic Opportunity to Reshape Middle East
Dating Apps Surge in Saudi Arabia as Social Norms Rapidly Evolve Among Youth
Saudi Arabia Detains Over Fourteen Thousand Illegal Residents in Week-Long Enforcement Drive
Saudi Foreign Minister Engages in Diplomatic Talks with Pakistan, Kuwait and Latvia on Regional Developments
Saudi Arabia Intercepts Cruise Missile as Regional Tensions Intensify
Saudi Stock Market Edges Higher as Tadawul Index Records Modest Gain
Underlying Rivalry Between Saudi Arabia and UAE Persists Despite Temporary Calm
Saudi Arabia’s Non-Oil Sector Contracts in March as Regional Tensions Weigh on Business Activity
Saudi Arabia Unveils Ambition to Establish Prestigious Global Prize Rivaling the Nobel
Saudi Crown Prince to Engage Wall Street in Push for Investment and Economic Expansion
Iran Accuses Saudi Arabia and UAE After Downing of Chinese-Made Drone
Saudi Arabia Condemns Attack on Hospital in Sudan, Calls for Protection of Civilians
Coordinated Drone Strike Targets CIA Facility Within US Embassy in Saudi Arabia
Italy’s Meloni Prioritises Energy Security and Strait of Hormuz Stability During Gulf Tour
Uncertainty Emerges Over Timeline and Direction of Saudi Arabia’s Ambitious Ski Resort Project
UAE and Saudi Arabia Escalate Strategy with Drone Operations Targeting Iran
Trump Delivers Characteristic Remarks on Saudi Crown Prince Amid Intensifying Iran Conflict
Drone Strike on US Embassy in Riyadh Caused Greater Damage Than First Reported
Saudi Arabia Introduces Flexible Solutions for Expired Visas Amid Regional Disruptions
Saudi Arabia’s Online Car Market Accelerates with AI Pricing and Fully Digital Buying Experience
Saudi Arabia Reassesses Defence Strategy as Iranian Drone Threat Drives Shift in Military Partnerships
Drone Strikes Target Saudi Arabia, Kuwait and Bahrain as Regional Conflict Intensifies
Japan and Saudi Arabia Align Efforts to Ease Rising Tensions with Iran
Saudi Crown Prince and Italy’s Meloni Strengthen Strategic Ties in High-Level Talks
SpaceX Explores Potential Five Billion Dollar Investment from Saudi Sovereign Wealth Fund Ahead of IPO
Saudi Arabia Lifts Key Import Barriers to Expand Access for U.S. Beef Exports
Saudi Arabia Enforces Strict Travel Penalties for Visits to Restricted Countries
Italy’s Meloni Embarks on Strategic Gulf Tour to Address Energy Security and Regional Stability
Saudi Film Festival Rescheduled to Summer as Regional Tensions Continue
Saudi Arabia Reports Forty Two Point Six Billion Dollars in Foreign Tourist Spending in 2025
Saudi Crown Prince and Russian President Hold Strategic Call on Escalating Regional Crisis
Saudi Arabia Advances Rail Network as Strategic Alternative to Strait of Hormuz Shipping Route
Ruanyun Edai Launches Saudi Arabia Hub With Forecast of Ten Percent Revenue Growth
Greek Defence Minister Visits Troops in Saudi Arabia Following Successful Missile Interception
Saudi Arabia Expands Global Strategy With Focus on African Critical Minerals
SpaceX Explores Potential Five Billion Dollar Investment From Saudi Fund Ahead of Possible IPO
US Central Command Dismisses Iranian Claim of Mass Casualties Among American Personnel in Saudi Arabia
Co-Diagnostics to Establish Molecular Diagnostics Facility in Saudi Arabia Through Joint Venture
Trump Engages Saudi Crown Prince in Talks on Potential Iran Ceasefire
Saudi Arabia’s Sadara Suspends Operations as Supply Chain Disruptions Intensify
Saudi Arabia Accelerates Energy Shift by Trading Oil Revenues for Battery Investments
Saudi Arabia Introduces Flexible Options for Expired Visas Amid Regional Disruptions
Online Narratives Surge as Iran–US Tensions Spill Into Digital Arena Following Trump Remarks
Saudi Arabia Urges Trump to Seize Strategic Moment as UAE Weighs Ground Deployment
Saudi Arabia Redirects Nearly One Million Barrels of Oil Daily Away from Strait of Hormuz
Saudi Arabia Carries Out Execution of Businessman Linked to 2011 Qatif Unrest
Ukraine–Saudi Defense Pact Signals Rising Demand for Battlefield Expertise
Saudi Arabia Balances Diplomacy and Defense Preparedness Amid Iran Conflict
×