FakeAdBlocker

Malware

⚠️ Overview

FakeAdBlocker is a browser extension‑based trojan that masquerades as legitimate ad‑blocking software but functions as a downloader and information stealer. It was first documented in 2021 by Proofpoint’s threat research team, who observed it distributed through malvertising chains and fake software update prompts. The malware is attributed to a financially motivated criminal cluster using a malware‑as‑a‑service model, and it falls under the categories of adware, trojan downloader, and infostealer (MITRE ATT&CK technique T1204.002 – User Execution via Malicious File).

🔧 Technical Capabilities

FakeAdBlocker propagates primarily through malvertising that redirects users to fake ad‑blocker landing pages and through drive‑by downloads from compromised websites. Once installed, the extension abuses Chrome and Edge extension APIs to inject intrusive advertisements, log keystrokes, and exfiltrate browsing history and saved credentials via HTTPS beaconing to command‑and‑control (C2) servers. Persistence is achieved by writing a registry run key (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRunFakeAdBlocker) and by enrolling the extension for automatic updates that can silently deploy additional payloads. Evasion techniques include obfuscation of JavaScript code using base64 and AES encryption, domain generation algorithms (DGAs) to rotate C2 endpoints, and checks for sandbox environments or debugger presence (MITRE ATT&CK T1497 – Virtualization/Sandbox Evasion). The malware also uses steganography to hide configuration data inside image files retrieved from the C2.

📜 History & Notable Incidents

FakeAdBlocker first appeared in early 2021 and saw a major campaign in March 2022, where it compromised over 500,000 users globally according to a Zscaler ThreatLabz report (July 2022). No high‑profile corporate victims have been publicly named, but the malware has been linked to the distribution of secondary payloads such as the RedLine Stealer and Bumblebee loader. Law enforcement actions have not been reported, though multiple browser vendors have removed the malicious extensions from their stores after vendor notifications.

🔍 Detection Indicators

Known file hashes for the malicious extension CRX packages include MD5: 9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d (from a 2022 sample) and SHA‑256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (Kaspersky threat report). Behavioral indicators include illicit modifications to browser homepage settings, injection of